Loading
Prepare for Email to Become the Default Login ExperienceRead More
Enhance Salesforce with Code
Proof-of-Possession for Asset Tokens

Proof-of-Possession for Asset Tokens

If you construct an actor token holding the public key of your asset and sign it with your asset’s private key, Salesforce binds that public key into your asset token. This pattern allows for what’s known as Proof-of-Possession or Holder of Key. The asset can prove that it holds the private key corresponding to the public key that Salesforce binds into the cnf claim during issuance. Proof-of-Possession helps provide greater assurance that the token is being presented by the actual asset it was issued to.

Required Editions

Available in: both Salesforce Classic (not available in all orgs) and Lightning Experience
Available in: All Editions

The holder can prove possession of the private key by various mechanisms, including TLS mutual authentication, signing of the HTTP request, or signing of a challenge.

Learn more about implementing Proof-of-Possession at:

 
Loading
Salesforce Help | Article