Device Bound Session Credentials (DBSC)
Device Bound Session Credentials (DBSC) is a web standard that binds a browser session to a private key held in the device's hardware, so a session cookie stolen from that device stops working anywhere else. It is being developed in the W3C Web Application Security Working Group, which published a first public working draft in August 2025.
With DBSC, the site sends a Secure-Session-Registration header at sign-in, the browser generates a key pair and registers the public key, and the site issues short-lived cookies. When they expire, the browser calls the site's refresh endpoint and proves it still holds the private key, which on Windows Chrome protects with the Trusted Platform Module. An infostealer can copy the cookie but not the key, so the stolen session dies at the next refresh, within whatever short cookie lifetime the site sets. Chrome shipped DBSC on Windows in early 2026, and Google says it is on by default for Google accounts; other browsers and platforms have not yet shipped it, and each site must implement the registration and refresh endpoints to benefit. It complements, rather than replaces, sender-constrained tokens such as DPoP for APIs.
See also: session hijacking, session cookie theft, token theft, infostealer
Related on Start with Identity
- GlossaryBearer Token
A bearer token is a credential that grants access to whoever presents it, with no proof that the presenter is the party it was issued to. OAuth 2.0 defines how
- GlossaryAccount Takeover (ATO)
When an attacker gains control of a legitimate account, often via stolen credentials, phishing, or session theft. A leading cause of breaches and fraud. The dis
- GlossaryCAEP
Continuous Access Evaluation Protocol. A specification for communicating security-relevant session events, such as a credential change, a device falling out of
- BlogA hijacked AI coding assistant session spread Shai-Hulud to about 100 internal repositories
Mandiant describes an intrusion at an unnamed SaaS provider where a poisoned package, recommended through a developer's AI coding assistant session, led to stol
- BlogAkeyless ships Runtime Authority, authorising AI agents per action instead of per session
Agents hold no secrets and get no standing privilege. Every action is authorised at the moment it happens, and the audit trail links the originating prompt to t
- BlogAnthropic's own Claude escaped a security test, stole a vendor's credentials, and used them
During evaluations Anthropic believed were sandboxed, Claude models broke out of test environments and hit real infrastructure at three organizations, in one ca