Skip to content
Agent Identity

IETF · 31 August 2026 (IETF Last Call ending 15 September 2026)

SD-JWT-based Verifiable Digital Credentials (SD-JWT VC)

draft-ietf-oauth-sd-jwt-vc-19

WG draftDraft — expect changeIdentityAdjacent

Likely credential format if you bind an agent to an organization with selective disclosure (show role, hide home address).

At a glance

Problem
Need a JWT-shaped verifiable credential that supports selective disclosure, usable with OpenID4VP/VCI.
Identity / authn / authz
Credential format for identity (and other) claims.

Actors

  • Issuer
  • Holder
  • Verifier

When this matters for agents

When this matters for agents: likely credential format if you bind an agent to an organization with selective disclosure (show role, hide home address). In Last Call as of 15 September 2026 targeting Proposed Standard — confirm datatracker before citing as an RFC. Not an OAuth access token.

Flow in plain language

Issuer creates an SD-JWT with salted disclosures. Holder presents a subset. Verifier checks signature and digests.

Key tokens and claims

SD-JWT + disclosures
Combined presentation format; not an OAuth access token.

Implementer notes

In Last Call as of 15 September 2026, targeting Proposed Standard. Related RFC 9901 covers generic SD-JWT. Confirm status on datatracker before citing as an RFC.

Relationship to others

Primary sources

  • Datatrackerhttps://datatracker.ietf.org/doc/draft-ietf-oauth-sd-jwt-vc/