Expand description
ES256 JWS signing — the one signing primitive the OAuth flow needs.
Two things are signed with the confidential client’s key:
- the client assertion (
private_key_jwt), proving to the PDS’s token endpoint that we are the client named byclient_id, and - DPoP proofs, proving possession of the per-session DPoP key.
Both are compact JWS: base64url(header) . base64url(payload) . base64url(sig).
The detail worth stating, because getting it wrong produces a signature that
verifies nowhere: JOSE ECDSA signatures are the fixed-width r || s
form (64 bytes for P-256), not ASN.1 DER. A DER signature is the default
output of many ECDSA APIs and is silently accepted by nothing.