bk99.de entertain the web since 1997

RFC 7519: JWT: Signed claims in JSON format

Summary

RFC 7519 defines compact JSON Web Tokens for transferable claims with signature or encryption. Self-contained tokens reduce lookups and make immediate revocation harder. Flexible cryptography requires strict checking of algorithms and claims.

Ideas

  • Claims describe subject, issuer, audience and validity.
  • JWS signs tokens, JWE encrypts them.
  • The compact encoding fits into HTTP headers and URLs.

Remarks

  • RFC 7519 has the status “Proposed Standard”; current errata and successor documents should also be checked.

Recommendations

  • Allow only explicitly configured algorithms.
  • Check issuer, audience, expiry and signature completely.

References

Read the RFC at the RFC Editor

Search the Web Archive