Start with Identity
Protocols & Standards

Daniel Fett

Editor, SD-JWT and SD-JWT VC · Authlete · 12+ years in identity
Focus areas
OAuth SecurityFormal AnalysisSelective DisclosureFAPI
Notable work
  • Editor of the SD-JWT and SD-JWT VC specifications
  • Co-author of the OAuth 2.0 Security Best Current Practice and FAPI 2.0
  • Formal security analysis of OAuth, OpenID Connect, and FAPI 1.0

Bio

Daniel Fett did a PhD on formal methods for analyzing web security and then pointed those methods at the protocols this industry depends on, finding attacks on OAuth and OpenID Connect that human review had missed. He led the formal analysis of FAPI 1.0, co-authored the OAuth 2.0 Security Best Current Practice and FAPI 2.0, and edits the SD-JWT and SD-JWT VC specifications.

Profile built from public IETF, OpenID Foundation, and academic records.

Where their work shows up

Two distinct contributions. First, proof: a formal model that says a protocol is secure under stated assumptions is a different kind of claim from a working group's confidence, and OAuth 2.1 and FAPI 2.0 both carry that work. Second, SD-JWT, which is how a verifiable credential can be issued once and then presented with only some fields revealed, with the rest cryptographically hidden rather than merely omitted. That is the mechanism behind selective disclosure in the EUDI wallet and OpenID4VC.

Built from public information only. This is an independent profile and is not an endorsement by, or affiliation with, the person listed. Corrections: [email protected].