RFC 9781: A Concise Binary Object Representation (CBOR) Tag for Unprotected CBOR Web Token Claims Sets (UCCS)
Recent RFCs 2025-05-28
Summary:
This document defines the Unprotected CWT Claims Set (UCCS), a data
format for representing a CBOR Web Token (CWT) Claims Set without
protecting it by a signature, Message Authentication Code (MAC), or
encryption. UCCS enables the use of CWT claims in environments where
protection is provided by other means, such as secure communication
channels or trusted execution environments. This specification
defines a CBOR tag for UCCS and describes the UCCS format, its
encoding, and its processing considerations. It also discusses
security implications of using unprotected claims sets.