SD-JWT (Selective Disclosure JSON Web Token) is an IETF-specified extension to the JSON Web Token standard that allows an Issuer to create a signed token containing hashed claim values, from which the Holder can selectively reveal only the specific claims needed for a given presentation — without exposing other claims or enabling correlation across presentations. The mechanism uses SHA-256 salted disclosure objects appended to the base JWT; verifiers can validate revealed disclosures against the issuer signature whilst remaining blind to undisclosed claims. SD-JWT forms the primary credential format for the European Union’s eIDAS 2.0 digital identity wallet system.
Content
- The SD-JWT specification was initiated at the IETF OAuth Working Group in 2022 by Daniel Fett and Brian Campbell, motivated by a practical gap: W3C Verifiable Credentials supported selective disclosure via BBS+ signatures, but BBS+ requires new cryptographic libraries and is not universally hardware-supported, limiting deployment on constrained devices. SD-JWT reuses the ubiquitous JWT infrastructure — including JOSE (JSON Object Signing and Encryption) algorithms already supported by hardware security modules, mobile secure elements, and virtually every web framework — while adding selective disclosure through a hash-and-reveal mechanism that requires no new cryptographic primitives.
- The mechanism works as follows: during issuance, each potentially disclosable claim is transformed into a disclosure string comprising a random salt, the claim name, and the claim value, encoded as base64url. The SHA-256 hash of this string is placed in the JWT payload under a
_sdarray. The issuer signs the JWT normally. The holder stores both the signed JWT and all disclosure strings. When presenting to a verifier, the holder appends only the disclosure strings for claims the verifier requires; the verifier recomputes the hash for each disclosure and checks it against the_sdarray to confirm issuer signature coverage, without having any knowledge of undisclosed claims. - SD-JWT is the primary format specified for the European Digital Identity Wallet (EUDI Wallet) under eIDAS 2.0, covering credentials such as national identity cards, driving licences, professional qualifications, and healthcare data. It is supported in OpenID4VCI as a first-class issuance format and in OpenID4VP (OpenID for Verifiable Presentations) for presentation exchange. Major mobile operating system vendors and hardware security module vendors are adding native support, and open-source implementations in Python, Rust, Java, and TypeScript have proliferated to support the ecosystem.
- In 2024-2025, SD-JWT VC (the binding of SD-JWT to W3C Verifiable Credential semantics) has achieved substantial standardisation momentum and is referenced in both NIST digital identity guidelines and the ARF (Architecture Reference Framework) for the EUDI Wallet. Active areas of development include key binding mechanisms that bind a credential cryptographically to the holder’s device key (preventing credential sharing), and holder-binding proofs that demonstrate device possession during presentation. The specification is on track for RFC publication, after which it will transition from draft to normative standard status across the ecosystem.