In section 12.1 (Replay Attacks), the text states:
- use self-contained challenges while not storing the seen
challenges. This approach scales well, while only guaranteeing
freshness, but no replay protection within the limited time-
window chosen by the Authorization Server.
As this technique does not provide replay protection within the limited time-window, it should not be mentioned.