Specification
https://w3c.github.io/webappsec-dbsc/
Description
A protocol for sites to regularly request proof of possession of a private key. When user agents store key pairs in a TPM, this allows for a strong protection against cookie theft.
Documentation
https://developer.chrome.com/docs/web-platform/device-bound-session-credentials
Browser support
As of 2026-02-16, shipped in Chrome https://chromestatus.com/feature/5140168270413824
Specification
https://w3c.github.io/webappsec-dbsc/
Description
A protocol for sites to regularly request proof of possession of a private key. When user agents store key pairs in a TPM, this allows for a strong protection against cookie theft.
Documentation
https://developer.chrome.com/docs/web-platform/device-bound-session-credentials
Browser support
As of 2026-02-16, shipped in Chrome https://chromestatus.com/feature/5140168270413824