NIST’s token guidance is final. Identity teams still have to separate trust from proof.
NIST’s finalized IR 8587 gives agencies and cloud providers a clearer brief on token misuse, revocation and sharing signals, key handling, and high-level AI and post-quantum considerations. The available records support a checklist of questions, not a new universal mandate or proof of deployment outcomes.