System for Cross-Domain Identity Management Profile for Security Event Tokens
RFC 9967, “System for Cross-Domain Identity Management Profile for Security Event Tokens”, is a Proposed Standard document published in May 2026 by P. Hunt, N. Cam-Winget, M. Kiser, J. Schreiber. It updates RFC 7643, RFC 7644. The canonical text is published by the RFC Editor.
Abstract
This specification defines a set of System for Cross-domain Identity Management (SCIM) Security Events using the Security Event Token (SET) specification (RFC 8417) to enable the asynchronous exchange of messages between SCIM service providers and receivers.
This specification updates RFC 7643 by defining additional attributes for the "urn:ietf:params:scim:schemas:core:2.0:ServiceProviderConfig" schema, and it updates RFC 7644 with an optional new asynchronous SCIM request capability.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9967 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9966 Bootstrapped TLS Authentication with Proof of Knowledge
- RFC 9968 Report from the IAB Workshop on the Next Era of Network Management Operations
- RFC 9965 The eap.arpa
- RFC 9969 Report from the IAB Workshop on AI-CONTROL
- RFC 9964 ML-DSA for JSON Object Signing and Encryption and CBOR Object Signing and Encryption
- RFC 9963 Legacy RSASSA-PKCS1-v1_5 Code Points for TLS 1.3
- RFC 9962 A Decentralized Locator/ID Separation Protocol Mapping System
- RFC 9972 Advanced BGP Monitoring Protocol Statistics Types