RFC 9901: Selective disclosure for JWTs
Summary
RFC 9901 defines SD-JWT so that holders disclose only the claims they need from a signed record. Digital credentials do not have to choose between full disclosure and no verifiability. Data minimisation can be enforced cryptographically.
Ideas
- Issuers sign hash bindings instead of making all values visible.
- Holders choose suitable disclosures for each recipient.
- Key binding can tie possession to a key.
Remarks
- RFC 9901 has the status “Proposed Standard”; current errata and successor documents should also be checked.
Recommendations
- Request only the claims you actually need.
- Check issuer, disclosures, nonce and key binding.
References
Read the RFC at the RFC Editor
Links to the original source and the Web Archive open in a new tab.