A Concise Binary Object Representation Tag for Unprotected CBOR Web Token Claims Sets
RFC 9781, “A Concise Binary Object Representation Tag for Unprotected CBOR Web Token Claims Sets”, is a Proposed Standard document published in May 2025 by H. Birkholz, J. O'Donoghue, N. Cam-Winget, C. Bormann. The canonical text is published by the RFC Editor.
Abstract
This document defines the Unprotected CWT Claims Set (UCCS), a data format for representing a CBOR Web Token (CWT) Claims Set without protecting it by a signature, Message Authentication Code (MAC), or encryption. UCCS enables the use of CWT claims in environments where protection is provided by other means, such as secure communication channels or trusted execution environments. This specification defines a CBOR tag for UCCS and describes the UCCS format, its encoding, and its processing considerations. It also discusses security implications of using unprotected claims sets.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9781 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9780 Bidirectional Forwarding Detection for Multipoint Networks over Point-to-Multipoint MPLS Label Switched Paths
- RFC 9782 Entity Attestation Token Media Types
- RFC 9779 Performance Measurement for Segment Routing Networks with the MPLS Data Plane
- RFC 9783 Arm's Platform Security Architecture Attestation Token
- RFC 9778 IANA Considerations for Internet Group Management Protocols
- RFC 9784 Virtual Ethernet Segments for EVPN and Provider Backbone Bridge EVPN
- RFC 9777 Multicast Listener Discovery Version 2 for IPv6
- RFC 9785 Preference-Based EVPN Designated Forwarder Election