The “COSE and JOSE Registrations for WebAuthn Algorithms” specification has been updated to address feedback received since working group adoption. The one breaking change is changing the secp256k1 curve identifier for JOSE from “
P-256K” to “
secp256k1“, for reasons described by John Mattsson. The draft now also specifies that the SHA-256 hash function is to be used with “
ES256K” signatures – a clarification due to Matt Palmer.
The specification is available at:
An HTML-formatted version is also available at: