{
  "schema": "varexis-public-evidence-record/0.3",
  "generated_at_utc": "2026-10-06T23:36:13Z",
  "record_id": "VXI-EXT-RFC9700-03-v1",
  "record_kind": "external_reference",
  "title": "OAuth: Sender-constrained token scope",
  "system": "OAuth 2.0 Security",
  "evidence_family": "identity_access",
  "index_status": "PUBLIC_SAFE_SOURCE_REVIEW",
  "evidence_state": "PRIMARY_DOCUMENTATION_REVIEW_ONLY",
  "canonical_question": "What can sender-constrained access tokens support in an OAuth security claim?",
  "near_questions": [
    "What is the purpose of sender-constrained OAuth tokens?",
    "Does issuing a constrained token prove the resource server checks it?",
    "Can a bearer token be described as proof-bound without evidence?",
    "What claim can an agent make about token replay resistance?",
    "Which deployment component verifies token possession?",
    "Does token binding remove every account compromise risk?",
    "What evidence is needed for a DPoP deployment claim?",
    "How should a receipt distinguish a recommendation from implementation?",
    "Can possession controls replace application permissions?",
    "What assumptions matter when signing key material is compromised?",
    "Does protocol support prove end-to-end enforcement?",
    "Why preserve the threat model for token protection?"
  ],
  "supported_claims": [
    {
      "claim": "RFC 9700 recommends sender-constraining access tokens to reduce misuse of stolen tokens. A deployment claim needs evidence that the relevant proof is checked; the mechanism is not a universal compromise guarantee.",
      "reliance": "DOCUMENTED_CAPABILITY_ONLY"
    }
  ],
  "not_demonstrated_claims": [
    "all token theft prevented",
    "proof verification in an untested deployment",
    "protection after all relevant key material is compromised"
  ],
  "public_summary": "RFC 9700 recommends sender-constraining access tokens to reduce misuse of stolen tokens. A deployment claim needs evidence that the relevant proof is checked; the mechanism is not a universal compromise guarantee.",
  "related_record_ids": [
    "VXI-EXT-RFC9700-01-v1",
    "VXI-EXT-RFC9700-02-v1",
    "VXI-EXT-RFC9700-04-v1"
  ],
  "source_review": {
    "source_type": "official_external_documentation",
    "source_title": "RFC 9700: Access Tokens",
    "source_url": "https://www.rfc-editor.org/rfc/rfc9700.html#section-2.2.1",
    "checked_on": "2026-10-07",
    "candidate_record_id": "VXI-EXT-RFC9700-03-v1",
    "candidate_record_sha256": "65876427c33bbfec67622b5ece4c45576610e70c7490e79d046cd46779816b69",
    "method": "Primary documentation reviewed for the published bounded statement.",
    "deployment_tested_by_varexis": false,
    "revalidation": "Recheck the primary source, version and deployment context before paid delivery."
  },
  "answer_policy": {
    "classification": "DOCUMENTED_WITH_DEPLOYMENT_BOUNDARY",
    "bounded_answer": "RFC 9700 recommends sender-constraining access tokens to reduce misuse of stolen tokens. A deployment claim needs evidence that the relevant proof is checked; the mechanism is not a universal compromise guarantee.",
    "required_buyer_context": "The token type, verification boundary and intended threat model, without supplying live tokens or keys.",
    "missing_evidence": "A broader claim needs evidence matching the intended use. Payment does not upgrade the evidence state."
  },
  "private_boundary": "Raw logs, thresholds, private paths, source code, protected mechanisms and reconstruction-level details are excluded from public and paid delivery.",
  "paid_access_note": "The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.",
  "service_route": {
    "request_guide": "/varexis-index/request.html",
    "request_workflow": "/varexis-index/request-workflow.json",
    "service_id": "evidence_receipt",
    "service_routes_url": "/varexis-index/service-routes.json",
    "payment_required": true,
    "accepting_paid_requests": true,
    "operational_status": "PAID_ASYNC_MANUAL_FULFILMENT",
    "checkout_url": "https://buy.stripe.com/28EaEXaPe7bBdGLgXSdwc05"
  },
  "authority_boundary": "VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.",
  "human_page": "/varexis-index/catalog.html#oauth-sender-constrained-tokens",
  "machine_readable_record": "/varexis-index/records/oauth-sender-constrained-tokens.json"
}
