Skip to Main Content
HCL Domino Ideas Portal

Welcome to the #dominoforever Product Ideas Forum! The place where you can submit product ideas and enhancement request. We encourage you to participate by voting on, commenting on, and creating new ideas. All new ideas will be evaluated by HCL Product Management & Engineering teams, and the next steps will be communicated. While not all submitted ideas will be executed upon, community feedback will play a key role in influencing which ideas are and when they will be implemented.


For more information on products and upcoming events around #dominoforever, please visit: HCL Domino Page


Status Needs Review
Workspace Domino
Categories Integration
Created by Guest
Created on Sep 28, 2026

Support JWE-encrypted JWT tokens for OIDC/OAuth in Domino (and Domino REST API)

Domino (and Domino REST API) currently support authentication using signed JWT/JWS tokens, but JWE-encrypted JWT tokens are not supported.

Please add JWE (JSON Web Encryption) support to both the Domino OIDC authentication layer and Domino REST API, ideally in the common Domino Core / idpcat.nsf token validation layer so that Domino REST API can use the same implementation.

JWE is a standard part of the JOSE/JWT ecosystem and is used by both OpenID Connect and OAuth specifications.

OpenID Connect Core explicitly supports encrypted ID Tokens and specifies that, when an ID Token is both signed and encrypted, it must first be signed and then encrypted, resulting in a Nested JWT:

https://openid.net/specs/openid-connect-core-1_0-18.html#Signatures

For OAuth 2.0 access tokens, RFC 9068 – JWT Profile for OAuth 2.0 Access Tokens, Section 4 explicitly defines processing of encrypted JWT access tokens:

“If the JWT access token is encrypted, decrypt it…”

After decryption, the Resource Server performs the required JWT validation, including validation of the signature and token claims:

https://www.rfc-editor.org/rfc/rfc9068.html#section-4

JWE itself is standardized by RFC 7516 – JSON Web Encryption (JWE):

https://www.rfc-editor.org/rfc/rfc7516.html

Supporting only signed JWS tokens can create interoperability issues with standards-based Identity Providers that issue encrypted JWT access tokens. Adding JWE support would allow Domino (and Domino REST API) to interoperate with such providers without requiring provider-specific workarounds or disabling access-token encryption.

Ideally, the implementation should support signed-and-encrypted (Nested JWT) access tokens, where Domino first decrypts the outer JWE and then performs the existing signature and claims validation on the inner JWT/JWS.



References:

RFC 7516 – JSON Web Encryption (JWE)
https://www.rfc-editor.org/rfc/rfc7516.html

RFC 9068 §4 – JWT Profile for OAuth 2.0 Access Tokens
https://www.rfc-editor.org/rfc/rfc9068.html#section-4

OpenID Connect Core 1.0 §10 – Signatures and Encryption
https://openid.net/specs/openid-connect-core-1_0-18.html#SigEnc

  • Attach files