Hi all,

With SD-JWT now published as RFC 9901 congratulations.

I’d like to flag an individual draft that deliberately applies its 
selective-disclosure analysis in a neighboring document class:

https://datatracker.ietf.org/doc/draft-sabey-succession-receipts-sd/

It applies the salted-digest / disclosure-by-omission mechanism to plain JSON 
documents canonicalized with JCS (RFC 8785), rather than JWS; the underlying 
documents are signed receipts of authority succession between AI agents:

https://datatracker.ietf.org/doc/draft-sabey-succession-receipts/

The draft is explicit that it composes with SD-JWT rather than replacing or 
competing with it.

I’d particularly value review from this group on whether the security 
considerations correctly restate RFC 9901’s analysis for the non-JWS setting.

A public conformance corpus and an in-browser verifier are available here:

https://github.com/jsabes24/css-succession-receipts

Thanks,

Jaryn Sabey


_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to