Skip to main content

10. IANA Considerations

10.1. JSON Web Token Claims Registry​

This specification registers the following Claims in the IANA "JSON Web Token Claims" registry.

10.1.1. Registration Template​

Claim Name:
The name of the Claim, as a case-sensitive string.

Claim Description:
A brief description of the Claim.

Change Controller:
For Standards Track RFCs, list "IESG". For others, give the name of the responsible party or organization.

Specification Document(s):
Reference to the document(s) that define the Claim.

10.1.2. Initial Registry Contents​

  • Claim Name: iss
    Claim Description: Issuer
    Change Controller: IESG
    Specification Document(s): RFC 7519, Section 4.1.1

  • Claim Name: sub
    Claim Description: Subject
    Change Controller: IESG
    Specification Document(s): RFC 7519, Section 4.1.2

  • Claim Name: aud
    Claim Description: Audience
    Change Controller: IESG
    Specification Document(s): RFC 7519, Section 4.1.3

  • Claim Name: exp
    Claim Description: Expiration Time
    Change Controller: IESG
    Specification Document(s): RFC 7519, Section 4.1.4

  • Claim Name: nbf
    Claim Description: Not Before
    Change Controller: IESG
    Specification Document(s): RFC 7519, Section 4.1.5

  • Claim Name: iat
    Claim Description: Issued At
    Change Controller: IESG
    Specification Document(s): RFC 7519, Section 4.1.6

  • Claim Name: jti
    Claim Description: JWT ID
    Change Controller: IESG
    Specification Document(s): RFC 7519, Section 4.1.7

10.2. Sub-Namespace Registration​

10.2.1. Registry Contents​

This specification registers the following value in the IANA "OAuth URI" registry:

URN: urn:ietf:params:oauth:token-type:jwt
Common Name: JSON Web Token (JWT) Token Type
Change Controller: IESG
Specification Document(s): RFC 7519, Section 9

10.3. Media Type Registration​

10.3.1. Registry Contents​

This section registers the "application/jwt" media type [RFC2046], which can be used to indicate that content is a JWT.

Type name: application
Subtype name: jwt
Required parameters: N/A
Optional parameters: N/A
Encoding considerations: 8bit; JWT values are encoded as a series of base64url-encoded values (some of which may be the empty string), separated by period ('.') characters.
Security considerations: See RFC 7519, Section 11
Interoperability considerations: N/A
Published specification: RFC 7519
Applications that use this media type: OpenID Connect, Mozilla Persona, Salesforce, Google, Android, Windows Azure, Amazon Web Services, and others
Additional information:

  • Magic number(s): N/A
  • File extension(s): N/A
  • Macintosh file type code(s): N/A
    Person & email address to contact for further information: Michael B. Jones, [email protected]
    Intended usage: COMMON
    Restrictions on usage: none
    Author: Michael B. Jones, [email protected]
    Change controller: IESG
    Provisional registration? No

10.4. Header Parameter Names Registration​

10.4.1. Registry Contents​

This specification registers the following Header Parameter names in the IANA "JSON Web Signature and Encryption Header Parameters" registry:

Header Parameter Name: iss
Header Parameter Description: Issuer
Header Parameter Usage Location(s): JWE
Change Controller: IESG
Specification Document(s): RFC 7519, Section 5.3

Header Parameter Name: sub
Header Parameter Description: Subject
Header Parameter Usage Location(s): JWE
Change Controller: IESG
Specification Document(s): RFC 7519, Section 5.3

Header Parameter Name: aud
Header Parameter Description: Audience
Header Parameter Usage Location(s): JWE
Change Controller: IESG
Specification Document(s): RFC 7519, Section 5.3