“JSON Web Key (JWK) Thumbprint,” for which Mike Jones and I are credited as co-authors, has been published as [RFC 7638].
This specification defines a method for calculating a stable hash value for a JSON Web Key (JWK). Specifically, it describes which JWK fields are used to calculate the hash value, how those fields are normalized, how the resulting Unicode string is converted to a byte sequence, and how the hash value is obtained from that byte sequence. The resulting hash value can be used to identify and select a JWK that contains the key in question.
I would like to express my deep gratitude to James Manger, John Bradley, Mike Jones, who once again made tremendous contributions, and everyone who participated in reviewing the security aspects of this specification. I would also like to thank everyone in the JOSE working group, its chairs, the Area Directors, and everyone at the IETF who was involved in developing this specification.
I should also note that this JWK Thumbprint is used as the value of the “sub” (subject) claim in an OpenID Connect self-issued ID Token.
[RFC 7638] Jones, M., N. Sakimura:JSON Web Key (JWK) Thumbprint, (2015/9), https://tools.ietf.org/html/rfc7638
Related posts

I Will Appear on the Okinawa Open Days Panel “Current and Future OSS Initiatives in Economic Security”
It is already the day of the event—in fact, I am writing this now (12/4 9:45) at my desk while preparing for the panel—but I will…

OpenAI Launches Sign in with ChatGPT (Based on OpenID Connect)
(Work in progress; last updated 2026-10-02 12:39 JST) On September 29, at DevDay 2026, OpenAI officially announced Sign in with ChatGPT (SIWC). I would like to…

When Software Becomes Staff: Governance, Security, and Safety for Agentic AI
Below is the transcript of my keynote speech at EIC 2026 on May 19, 2026. The slides are provided as a PDF at the end of…
