The protocol is intentionally small. Prefer additions that improve interoperability, conformance, safety, or developer ergonomics without creating a hosted-service dependency.
Before proposing a new field, ask:
- Is it part of identity, authority, delegation, enforcement, evidence, or lifecycle?
- Can an existing standard already express it?
- Can it be optional without creating incompatible implementations?
- Does the field create authority accidentally?
Security-sensitive changes should include adversarial tests and a threat-model note.