> Apologies if this is dealt with elsewhere, but does the standard address how should one deal with signing JSON data?

There's work in this area: [JWS](, a proposed standard at the IETF, and [Linked Data Signatures](, work from the Web Payments and Credentials CGs at W3C.

