Signing
RS256 (2048-bit RSA)
JWT access tokens, 1h TTL
HKDF key derivation
AES-256-GCM envelope encryption
Private keys encrypted at rest
Protection
PKCE mandatory (S256 only)
Refresh token rotation
Token family replay detection
Redirect URI SSRF protection
Rate limiting on all endpoints
Token revocation (immediate)