December 28, 2012
December 27, 2012 OAuth JWT & Assssertions Release

OAuth logoNew versions of the OAuth JWT, JWT Bearer Profile, and Assertions specs have been released incorporating feedback since IETF 85 in Atlanta. The primary change is changing the name of the “prn” claim to “sub” (subject) both to more closely align with SAML name usage and to use a more intuitive name for this concept. (Also, see the related coordinated change to the OpenID Connect specifications.) The definition of the “aud” (audience) claim was also extended to allow JWTs to have multiple audiences (a feature also in SAML assertions).

An explanation was added to the JWT spec about why should be signed and then encrypted.

The audience definition in the Assertions specification was relaxed so that audience values can be OAuth “client_id” values. Informative references to the SAML Bearer Profile and JWT Bearer Profile specs were also added.

This release incorporates editorial improvements suggested by Jeff Hodges, Hannes Tschofenig, and Prateek Mishra in their reviews of the JWT specification. Many of these simplified the terminology usage. See the Document History section of each specification for more details about the changes made.

This release is part of a coordinated release of JOSE, OAuth, and OpenID Connect specifications. You can read about the other releases here: JOSE Release Notes, OpenID Connect Release Notes.

The new specification versions are:

HTML formatted versions are available at:

3 Responses to “December 27, 2012 OAuth JWT & Assssertions Release”

  1. Mike Jones: self-issued » December 27, 2012 JOSE Release on 28 Dec 2012 at 4:49 pm #

    [...] of JOSE, OAuth, and OpenID Connect specifications. You can read about the other releases here: OAuth Release Notes, OpenID Connect Release [...]

  2. Mike Jones: self-issued » December 27, 2012 OpenID Connect Release on 28 Dec 2012 at 4:50 pm #

    [...] December 27, 2012 OAuth JWT & Assssertions Release December 28, 2012 December 27, 2012 OpenID Connect [...]

  3. IETF JOSE, OAuth JWT and Assertions, and OpenID Connect spec releases | Backfill for 'Note to Self' on 30 Dec 2012 at 10:19 pm #

    [...] http://t.co/K6i0ry5C -> here [...]

Trackback URI | Comments RSS

Leave a Reply

You must be logged in to post a comment.