Domino (and Domino REST API) currently support authentication using signed JWT/JWS tokens, but JWE-encrypted JWT tokens are not supported.
Please add JWE (JSON Web Encryption) support to both the Domino OIDC authentication layer and Domino REST API, ideally in the common Domino Core / idpcat.nsf token validation layer so that Domino REST API can use the same implementation.
JWE is a standard part of the JOSE/JWT ecosystem and is used by both OpenID Connect and OAuth specifications.
OpenID Connect Core explicitly supports encrypted ID Tokens and specifies that, when an ID Token is both signed and encrypted, it must first be signed and then encrypted, resulting in a Nested JWT:
https://openid.net/specs/openid-connect-core-1_0-18.html#Signatures
For OAuth 2.0 access tokens, RFC 9068 – JWT Profile for OAuth 2.0 Access Tokens, Section 4 explicitly defines processing of encrypted JWT access tokens:
“If the JWT access token is encrypted, decrypt it…”
After decryption, the Resource Server performs the required JWT validation, including validation of the signature and token claims:
https://www.rfc-editor.org/rfc/rfc9068.html#section-4
JWE itself is standardized by RFC 7516 – JSON Web Encryption (JWE):
https://www.rfc-editor.org/rfc/rfc7516.html
Supporting only signed JWS tokens can create interoperability issues with standards-based Identity Providers that issue encrypted JWT access tokens. Adding JWE support would allow Domino (and Domino REST API) to interoperate with such providers without requiring provider-specific workarounds or disabling access-token encryption.
Ideally, the implementation should support signed-and-encrypted (Nested JWT) access tokens, where Domino first decrypts the outer JWE and then performs the existing signature and claims validation on the inner JWT/JWS.
References:
RFC 7516 – JSON Web Encryption (JWE)
https://www.rfc-editor.org/rfc/rfc7516.html
RFC 9068 §4 – JWT Profile for OAuth 2.0 Access Tokens
https://www.rfc-editor.org/rfc/rfc9068.html#section-4
OpenID Connect Core 1.0 §10 – Signatures and Encryption
https://openid.net/specs/openid-connect-core-1_0-18.html#SigEnc