The Entity Attestation Token
RFC 9711, “The Entity Attestation Token”, is a Proposed Standard document published in April 2025 by L. Lundblade, G. Mandyam, J. O'Donoghue, C. Wallace. The canonical text is published by the RFC Editor.
Abstract
An Entity Attestation Token (EAT) provides an attested claims set that describes the state and characteristics of an entity, a device such as a smartphone, an Internet of Things (IoT) device, network equipment, or such. This claims set is used by a relying party, server, or service to determine the type and degree of trust placed in the entity.
An EAT is either a CBOR Web Token (CWT) or a JSON Web Token (JWT) with attestation-oriented claims.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9711 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9710 Simple Fixes to the IP Flow Information Export Entities IANA Registry
- RFC 9712 IETF Meeting Venue Requirements Review
- RFC 9709 Encryption Key Derivation in the Cryptographic Message Syntax Using HKDF with SHA-256
- RFC 9713 Bundle Protocol Version 7 Administrative Record Types Registry
- RFC 9708 Use of the HSS/LMS Hash-Based Signature Algorithm in the Cryptographic Message Syntax
- RFC 9714 Encapsulation for MPLS Performance Measurement with the Alternate- Marking Method
- RFC 9707 Report from the IAB Workshop on Barriers to Internet Access of Services
- RFC 9715 IP Fragmentation Avoidance in DNS over UDP