RFC 7797 · PROPOSED STANDARD · 2016

JSON Web Signature Unencoded Payload Option

Overview

RFC 7797, “JSON Web Signature Unencoded Payload Option”, is a Proposed Standard document published in February 2016 by M. Jones. It updates RFC 7519. The canonical text is published by the RFC Editor.

Abstract

JSON Web Signature (JWS) represents the payload of a JWS as a base64url-encoded value and uses this value in the JWS Signature computation. While this enables arbitrary payloads to be integrity protected, some have described use cases in which the base64url encoding is unnecessary and/or an impediment to adoption, especially when the payload is large and/or detached. This specification defines a means of accommodating these use cases by defining an option to change the JWS Signing Input computation to not base64url- encode the payload. This option is intended to broaden the set of use cases for which the use of JWS is a good fit.

This specification updates RFC 7519 by stating that JSON Web Tokens (JWTs) MUST NOT use the unencoded payload option defined by this specification.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 7797 is hosted at rfc-editor.org. Available in TXT,HTML.

Relationships to other RFCs
This RFC updates
RFC 7519
Other RFCs from 2016

Who Is Online

In total there are 61 users online: 0 registered, 57 guests and 4 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: Applebot Googlebot Other Bot SemrushBot

Users active in the past 15 minutes. Total registered members: 354