Skip to main content

Proof-of-Possession Key Semantics for JSON Web Tokens (JWTs)
RFC 7800

Approval announcement
Draft of message to be sent after approval:


From: The IESG <>
To: "IETF-Announce" <>
Cc:,,,, "The IESG" <>,,
Subject: Protocol Action: 'Proof-of-Possession Key Semantics for JSON Web Tokens (JWTs)' to Proposed Standard (draft-ietf-oauth-proof-of-possession-11.txt)

The IESG has approved the following document:
- 'Proof-of-Possession Key Semantics for JSON Web Tokens (JWTs)'
  (draft-ietf-oauth-proof-of-possession-11.txt) as Proposed Standard

This document is the product of the Web Authorization Protocol Working

The IESG contact persons are Stephen Farrell and Kathleen Moriarty.

A URL of this Internet Draft is:

Ballot Text

Technical Summary

   This specification defines how to express a declaration in a JSON Web
   Token (JWT) that the presenter of the JWT possesses a particular key
   and that the recipient can cryptographically confirm proof-of-
   possession of the key by the presenter.  This property is also
   sometimes described as the presenter being a holder-of-key.

Working Group Summary

The document was developed by the working group based on the
requirements and architecture described in
There is strong consensus behind this work.

Document Quality

There is at least one implementation of this draft
confirmed on the OAuth mailing list.


    Kepeng Li is the document shepherd and
    Kathleen Moriarty is the responsible AD.


     This specification establishes the IANA "JWT Confirmation Methods"
     registry for JWT "cnf" member values with Specification Required [RFC5226]
     and designated expert review on the
     mailing list. 

     CNF value is also added to the registry established in RFC7519

RFC Editor Note