The IESG has approved the following document: - 'JSON Web Token Best Current Practices' (draft-ietf-oauth-rfc8725bis-10.txt) as Best Current Practice
This document is the product of the Web Authorization Protocol Working Group. The IESG contact persons are Christopher Inacio and Deb Cooley. A URL of this Internet-Draft is: https://datatracker.ietf.org/doc/draft-ietf-oauth-rfc8725bis/ Technical Summary JSON Web Tokens, also known as JWTs, are URL-safe JSON-based security tokens that contain a set of claims that can be signed and/or encrypted. JWTs are being widely used and deployed as a simple security token format in numerous protocols and applications, both in the area of digital identity and in other application areas. This Best Current Practices (BCP) specification updates RFC 7519 to provide actionable guidance leading to secure implementation and deployment of JWTs. This BCP specification furthermore replaces the existing JWT BCP specification RFC 8725 to provide additional actionable guidance covering threats and attacks that have been discovered since RFC 8725 was published. Working Group Summary There was broad consensus and no controversy. The document provides security recommendations derived from known attacks. Implementations that do not follow these recommendations are likely to be vulnerable. Document Quality This document primarily addresses implementation and configuration issues observed in real‑world deployments. It has been shared with implementers, who have provided feedback incorporated into the current version. Downrefs: RFC 6979, and RFC 8017 - both are already in the downref registry. Personnel The Document Shepherd for this document is Hannes Tschofenig. The Responsible Area Director is Deb Cooley. _______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
