Brian, For a nonce-based replay protection you. might want to look at the ACME protocol here: https://tools.ietf.org/html/rfc8555#section-6.5
Regards, Rifaat
_______________________________________________ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth