The IETF OAuth working group has adopted the JWK Thumbprint URI specification. The abstract of the specification is:
This specification registers a kind of URI that represents a JSON Web Key (JWK) Thumbprint value. JWK Thumbprints are defined in RFC 7638. This enables JWK Thumbprints to be used, for instance, as key identifiers in contexts requiring URIs.
The need for this arose during specification work in the OpenID Connect working group. In particular, JWK Thumbprint URIs are used as key identifiers that can be syntactically distinguished from other kinds of identifiers also expressed as URIs in the Self-Issued OpenID Provider v2 specification.
Given that the specification does only one simple thing in a straightforward manner, we believe that it is ready for working group last call.
The specification is available at:
Leave a Reply
You must be logged in to post a comment.