Skip to Main Content
Cloud Platform


This is an IBM Automation portal for Cloud Platform products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.


Status Future consideration
Workspace WebSphere Liberty
Created by Guest
Created on Jun 8, 2026

Enable DPoP support on OAuth 2.0 under z/OS Connect Enterprise Edition

We have noticed several types of frauds when using tokens via OAuth 2.0. To address this issue, RFC 9449 was published with the implementation of DPoP (Demonstrating Proof of Possession.)

"DPoP is an OAuth security extension for binding tokens to a private key that belongs to the client. The binding makes the DPoP access token sender-constrained and its replay, if leaked or stolen token, can be effectively detected and prevented, as opposed to the common Bearer token."

It's very important to implement it on z/OS Connect / Liberty to mitigate these issues. Could you please help us with it?

Idea priority Urgent
  • Guest
    Jun 9, 2026

    Great Idea !!!

  • Guest
    Jun 8, 2026

    This is an important security feature for my customer.

  • Guest
    Jun 8, 2026

    It would be great for clients

  • Guest
    Jun 8, 2026

    This functionality is crucial for expanding the product’s use in mission-critical environments.

  • Guest
    Jun 8, 2026

    Great!!! i'm deal!

  • Guest
    Jun 8, 2026

    This feature is key for a use case that I'm pushing to increase the usage of the solution.

  • Guest
    Jun 8, 2026

    Without this DPoP support, the expansion of z/OS Connect within my client's infrastructure will be at high risk.

  • Guest
    Jun 8, 2026

    It is an excellent idea, and you have my support.

  • Guest
    Jun 8, 2026

    It is crucial for the client I work with

  • Guest
    Jun 8, 2026

    I'm on board with that. 

  • Guest
    Jun 8, 2026

    Very important this implementation.