bk99.de entertain the web since 1997

RFC 9901: Selective disclosure for JWTs

Summary

RFC 9901 defines SD-JWT so that holders disclose only the claims they need from a signed record. Digital credentials do not have to choose between full disclosure and no verifiability. Data minimisation can be enforced cryptographically.

Ideas

  • Issuers sign hash bindings instead of making all values visible.
  • Holders choose suitable disclosures for each recipient.
  • Key binding can tie possession to a key.

Remarks

  • RFC 9901 has the status “Proposed Standard”; current errata and successor documents should also be checked.

Recommendations

  • Request only the claims you actually need.
  • Check issuer, disclosures, nonce and key binding.

References

Read the RFC at the RFC Editor

Search the Web Archive