6 releases

0.3.0 Jan 20, 2025
0.2.1 Mar 12, 2024
0.2.0 Feb 5, 2024
0.1.2 Jan 14, 2024
0.1.0 Dec 11, 2023

#285 in Cryptography

Download history 54/week @ 2024-11-15 213/week @ 2024-11-22 161/week @ 2024-11-29 128/week @ 2024-12-06 75/week @ 2024-12-13 7/week @ 2024-12-20 6/week @ 2024-12-27 40/week @ 2025-01-03 71/week @ 2025-01-10 217/week @ 2025-01-17 55/week @ 2025-01-24 42/week @ 2025-01-31 52/week @ 2025-02-07 121/week @ 2025-02-14 310/week @ 2025-02-21 324/week @ 2025-02-28

817 downloads per month
Used in 2 crates (via identity_credential)


1.5K SLoC

Apache 2.0 license Discord StackExchange

SD-JWT Reference implementation

Rust implementation of the Selective Disclosure for JWTs (SD-JWT) version 12


This library supports

  • Issuing SD-JWTs:
    • Create a selectively disclosable JWT by choosing which properties can be concealed from a verifier. Concealable claims are replaced with their disclosure's digest.
    • Adding decoys to both JSON objects and arrays.
    • Requiring an holder's key-bind.
  • Managing SD-JWTs
    • Conceal with ease any concealable property.
    • Insert a key-bind.
  • Verifying SD-JWTs
    • Recursively replace digests in objects and arrays with their corresponding disclosure value.

Sha-256 hash function is shipped by default, encoding/decoding with other hash functions is possible.

Getting started

Include the library in your cargo.toml.

sd-jwt-payload = { version = "0.3.0" }


See sd_jwt.rs for a runnable example.


This library consists of the major structs:

  1. SdJwtBuilder: creates SD-JWTs.
  2. SdJwt: handles SD-JWTs.
  3. Disclosure: used throughout the library to represent disclosure objects.
  4. Hasher: a trait to provide hash functions create and replace disclosures.
  5. Sha256Hasher: implements Hasher for the Sha-256 hash function.
  6. JwsSigner: a trait used to create JWS signatures.


Any JSON object can be used to create an SD-JWT:

  let object = json!({
    "sub": "user_42",
    "given_name": "John",
    "family_name": "Doe",
    "email": "johndoe@example.com",
    "phone_number": "+1-202-555-0101",
    "phone_number_verified": true,
    "address": {
      "street_address": "123 Main St",
      "locality": "Anytown",
      "region": "Anystate",
      "country": "US"
    "birthdate": "1940-01-01",
    "updated_at": 1570000000,
    "nationalities": [
  let builder: SdJwtBuilder = SdJwtBuilder::new(object);

This creates a stateful builder with Sha-256 hash function by default to create disclosure digests.

Note: SdJwtBuilder is generic over Hasher which allows custom encoding with other hash functions.

The builder can encode any of the object's values or array elements, using the make_concealable method. Suppose the value of street_address in 'address' should be selectively disclosed as well as the entire value of address and the first phone value.


Note: the make_concealable method takes a JSON Pointer to determine the element to conceal inside the JSON object.

The builder also supports adding decoys. For instance, the amount of phone numbers and the amount of claims need to be hidden.

    .add_decoys("/nationalities", 1)? // Adds 1 decoys to the array `nationalities`.
    .add_decoys("", 2)? // Adds 2 decoys to the top level object.

Through the builder an issuer can require a specific key-binding that will be verified upon validation:


Internally, builder's object now looks like:

  "_sd": [
  "_sd_alg": "sha-256",
  "cnf": {
    "kid": "key1"
  "sub": "user_42",
  "given_name": "John",
  "family_name": "Doe",
  "nationalities": [
      "...": "xYpMTpfay0Rb77IWvbJU1C4JT3kvJUftZHxZuwfiS1M"
      "...": "GqcdlPi6GUDcj9VVpm8kj29jfXCdyBx2GfWP34339hI"
  "phone_number_verified": true,
  "updated_at": 1570000000,
  "birthdate": "1940-01-01"

Note: no JWT claims like exp or iat are added. If necessary, these need to be added and validated manually.

To create the actual SD-JWT the finish method must be called on the builder:

  let signer = MyHS256Signer::new(); 
  let sd_jwt = builder
    // ...
    .finish(&signer, "ES256")


Once an SD-JWT is obtained, any concealable property can be omitted from it by creating a presentation and calling the conceal method:

  let mut sd_jwt = SdJwt::parse("...")?;
  let hasher = Sha256Hasher::new();
  let (presented_sd_jwt, removed_disclosures) = sd_jwt

To attach a key-binding JWT (KB-JWT) the KeyBindingJwtBuilder struct can be used:

  let mut sd_jwt = SdJwt::parse("...")?;
  // Can be used to check which key is required - if any.
  let requird_kb: Option<&RequiredKeyBinding> = sd_jwt.required_key_binding();

  let signer = MyJwkSigner::new();
  let hasher = Sha256Hasher::new();
  let kb_jwt = KeyBindingJwtBuilder::new()
    .finish(&sd_jwt, &hasher, "ES256", &signer)
  let (sd_jwt, _) = sd_jwt.into_presentation(&hasher)?


The SD-JWT can be turned into a JSON object of its disclosed values by calling the into_disclosed_object method:

  let mut sd_jwt = SdJwt::parse("...")?;
  let disclosed_object = sd_jwt.into_disclosed_object(&hasher)?;


  "address": {
    "country": "US",
    "locality": "Anytown",
    "region": "Anystate",
    "street_address": "123 Main St"
  "phone_number": "+1-202-555-0101",
  "cnf": {
    "kid": "key1"
  "sub": "user_42",
  "given_name": "John",
  "family_name": "Doe",
  "nationalities": [
  "phone_number_verified": true,
  "updated_at": 1570000000,
  "birthdate": "1940-01-01"


  • _sd_alg property was removed.


Contributions are what make the open source community such an amazing place to learn, inspire, and create. Any contributions you make are greatly appreciated.

If you have a suggestion that would make this better, please fork the repo and create a pull request. You can also simply open an issue with the tag "enhancement". Don't forget to give the project a star! Thanks again!

  1. Fork the Project
  2. Create your Feature Branch (git checkout -b feature/AmazingFeature)
  3. Commit your Changes (git commit -m 'Add some AmazingFeature')
  4. Push to the Branch (git push origin feature/AmazingFeature)
  5. Open a Pull Request

(back to top)


Distributed under the Apache License. See LICENSE for more information.

(back to top)


~103K SLoC