[OAUTH-WG] I-D Action: draft-ietf-oauth-rfc8725bis-09.txt
internet-drafts@ietf.org Tue, 11 August 2026 20:02 UTC
Return-Path: <internet-drafts@ietf.org>
X-Original-To: oauth@ietf.org
Delivered-To: oauth@mail2.ietf.org
Received: from [10.244.8.24] (gaia.k8s.ietf.org [4.156.85.76]) by mail2.ietf.org (Postfix) with ESMTP id EFFB412811C35; Tue, 11 Aug 2026 13:02:28 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786478549; bh=4RlZRyD0T8f+azpleygkAoAcCu9AkldQGPTeSKDul2U=; h=From:To:Cc:Subject:Reply-To:Date; b=CqPNupLZuXyyfLj1J6qY7zwQqcor5lb4mP/bPi6aAOlbuWTea2MONt7skrfjcFH7u UhgwExiClOpkU5aEAt9Xln15/cVB9FLZosEqT5tjHbscfE33qMyFEW3HZwSZ1ldk4X I05iQd1bkdtCo3WFaLbCMUaaRtM4Em6Da0/gUuOo=
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 12.70.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <178647854890.494073.10374250210183541556@dt-datatracker-559c48c7fb-9llwz>
Date: Tue, 11 Aug 2026 13:02:28 -0700
Message-ID-Hash: EKMUXDB4PUL5FWLB3YLDEMPPAQSRP5PN
X-Message-ID-Hash: EKMUXDB4PUL5FWLB3YLDEMPPAQSRP5PN
X-MailFrom: internet-drafts@ietf.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-oauth.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: oauth@ietf.org
X-Mailman-Version: 3.3.9rc6
Reply-To: oauth@ietf.org
Subject: [OAUTH-WG] I-D Action: draft-ietf-oauth-rfc8725bis-09.txt
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/bZqq3rcJ9DnHiRfrYjB9C5ihiLY>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>
Internet-Draft draft-ietf-oauth-rfc8725bis-09.txt is now available. It is a
work item of the Web Authorization Protocol (OAUTH) WG of the IETF.
Title: JSON Web Token Best Current Practices
Authors: Yaron Sheffer
Dick Hardt
Michael B. Jones
Name: draft-ietf-oauth-rfc8725bis-09.txt
Pages: 25
Dates: 2026-08-11
Abstract:
JSON Web Tokens, also known as JWTs, are URL-safe JSON-based security
tokens that contain a set of claims that can be signed and/or
encrypted. JWTs are being widely used and deployed as a simple
security token format in numerous protocols and applications, both in
the area of digital identity and in other application areas. This
Best Current Practices (BCP) specification updates RFC 7519 to
provide actionable guidance leading to secure implementation and
deployment of JWTs.
This BCP specification furthermore obsoletes the existing JWT BCP
specification RFC 8725 to provide additional actionable guidance
covering threats and attacks that have been discovered since RFC 8725
was published.
The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-ietf-oauth-rfc8725bis/
There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-ietf-oauth-rfc8725bis-09.html
A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-ietf-oauth-rfc8725bis-09
Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts
- [OAUTH-WG] I-D Action: draft-ietf-oauth-rfc8725bi… internet-drafts