Application State { "next_url":"/account/settings", ... "foo":"bar" } ↓ Encrypt or Singed Application State (JWE or JWS String) Application State Hash SHA256 + Base64 URL Encoded String