Skip to content

Normatively define how an SD-JWT VC is returned in vp_token - #782

Merged
Sakurann merged 2 commits into
mainfrom
780-sd-jwt-vc-serialization
Aug 31, 2026
Merged

Sakurann merged 2 commits into
mainfrom
780-sd-jwt-vc-serialization

Conversation

@jogu

@jogu jogu commented Aug 20, 2026

Copy link
Copy Markdown
Collaborator

Specify that each SD-JWT VC presentation is a string containing an SD-JWT or SD-JWT+KB in the compact serialized format from Section 4 of the SD-JWT specification, and that the JWS JSON Serialization must not be used, as agreed in the working group discussion today.

closes #780

Specify that each SD-JWT VC presentation is a string containing an
SD-JWT or SD-JWT+KB in the compact serialized format from Section 4 of
the SD-JWT specification, and that the JWS JSON Serialization must not
be used, as agreed in the working group discussion today.

closes #780
@dpostnikov

Copy link
Copy Markdown
Collaborator

Discussed on the APAC call today:

  • Feedback from the WG was requested.
  • @jogu, to update for 1.0 as well?
  • "The JWS JSON Serialization defined in Section 8 of [@!I-D.ietf-oauth-selective-disclosure-jwt] MUST NOT be used." need to be further qualified.

@c2bo

c2bo commented Aug 26, 2026

Copy link
Copy Markdown
Member
  • @jogu, to update for 1.0 as well?

Agreed, this should imho go into 1.0 errata as well

@jogu
jogu force-pushed the 780-sd-jwt-vc-serialization branch from 5085c8a to 0b35786 Compare August 26, 2026 22:28
@jogu

jogu commented Aug 26, 2026

Copy link
Copy Markdown
Collaborator Author

Both points resolved. I did actually mean to put it into 1.0 errata but forget. Then remembered and forgot again. So I agree it should be there.

@brentzundel

Copy link
Copy Markdown
Collaborator

Discussion in group: We need to see if this is needed after #726. It may work to land this one anyway.

@jogu

jogu commented Aug 27, 2026 •

Copy link
Copy Markdown
Collaborator Author

Discussion in group: We need to see if this is needed after #726. It may work to land this one anyway.

Even if we reference a version of SD-JWT VC that includes the changes in https://github.com/oauth-wg/oauth-sd-jwt-vc/pull/425/changes I think we still need this text to make clear that, even if an ecosystem decides to fully define a JSON serialisation, that it needs to have a different credential format identifier than the compact serialisation.

@Sakurann
Sakurann merged commit 39fa073 into main Aug 31, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

It's not normatively defined how to return an SD-JWT VC

5 participants