# device-bound-session-credentials

Source: https://startwithidentity.com/glossary/device-bound-session-credentials/
Last updated: 2026-09-29
License: content by Start with Identity. Cite the source URL.

---

Device Bound Session Credentials (DBSC) is a web standard that binds a browser session to a private key held in the device's hardware, so a session cookie stolen from that device stops working anywhere else. It is being developed in the W3C Web Application Security Working Group, which published a first public working draft in August 2025.

With DBSC, the site sends a `Secure-Session-Registration` header at sign-in, the browser generates a key pair and registers the public key, and the site issues short-lived cookies. When they expire, the browser calls the site's refresh endpoint and proves it still holds the private key, which on Windows Chrome protects with the Trusted Platform Module. An infostealer can copy the cookie but not the key, so the stolen session dies at the next refresh, within whatever short cookie lifetime the site sets. Chrome shipped DBSC on Windows in early 2026, and Google says it is on by default for Google accounts; other browsers and platforms have not yet shipped it, and each site must implement the registration and refresh endpoints to benefit. It complements, rather than replaces, sender-constrained tokens such as [DPoP](https://startwithidentity.com/glossary/dpop/) for APIs.

See also: [session hijacking](https://startwithidentity.com/glossary/session-hijacking/), [session cookie theft](https://startwithidentity.com/techniques/session-cookie-theft/), [token theft](https://startwithidentity.com/glossary/token-theft/), [infostealer](https://startwithidentity.com/glossary/infostealer/)
