Daniel Fett
- Editor of the SD-JWT and SD-JWT VC specifications
- Co-author of the OAuth 2.0 Security Best Current Practice and FAPI 2.0
- Formal security analysis of OAuth, OpenID Connect, and FAPI 1.0
Bio
Daniel Fett did a PhD on formal methods for analyzing web security and then pointed those methods at the protocols this industry depends on, finding attacks on OAuth and OpenID Connect that human review had missed. He led the formal analysis of FAPI 1.0, co-authored the OAuth 2.0 Security Best Current Practice and FAPI 2.0, and edits the SD-JWT and SD-JWT VC specifications.
Profile built from public IETF, OpenID Foundation, and academic records.
Where their work shows up
Two distinct contributions. First, proof: a formal model that says a protocol is secure under stated assumptions is a different kind of claim from a working group's confidence, and OAuth 2.1 and FAPI 2.0 both carry that work. Second, SD-JWT, which is how a verifiable credential can be issued once and then presented with only some fields revealed, with the rest cryptographically hidden rather than merely omitted. That is the mechanism behind selective disclosure in the EUDI wallet and OpenID4VC.
Related on Start with Identity
- GlossaryBBS Signature
A signature scheme that lets a holder reveal only a subset of the fields in a credential while keeping the issuer's single signature valid, without the issuer's
- GlossaryDecentralized Identifier (DID)
A W3C standard identifier that a subject controls without a central registry, resolvable to a document with keys and endpoints. A building block of decentralize
- CVEKeycloak client policy enforcement flaw
A 2026 Keycloak client-policy enforcement bug. Client policies are how you ban implicit flow, require PKCE, or force FAPI. If they do not fire, the realm's writ
- GlossaryMobile Driver's License (mDL)
A driver's license issued to a phone wallet under the ISO/IEC 18013-5 standard, presentable in person and increasingly online. It supports selective disclosure,
- ExpertChairman
Nat Sakimura has chaired the OpenID Foundation for many years and is a primary author of the OpenID Connect specifications and the FAPI security profile used by
- ExpertCo-author of TLS 1.0 and the W3C DID specification
Christopher Allen co-authored the IETF TLS 1.0 specification, co-authored the W3C Decentralized Identifiers specification, and in 2016 published The Path to Sel