JWT claims reference
Every registered RFC 7519 claim, RFC 7515/7516 header parameter, OIDC and RFC 9068 claim, and common vendor claims from Microsoft Entra, Auth0, Okta, AWS Cognito, Firebase, Keycloak and Google.
iss— Issuer: Identifies the principal that issued the token, typically a URL or a stable identifier string. Verifiers should treat it as an index into a…sub— Subject: Identifies the principal the token is about — usually the authenticated user or service. Must be unique within the issuer's namespace (or…aud— Audience: Names the intended recipient(s) of the token — a single string or an array of strings. A verifier that fails to check its own identifier…exp— Expiration Time: Unix epoch seconds after which the token must be rejected. A very common decoder bug is treating this value as milliseconds (e.g. from…nbf— Not Before: Unix epoch seconds before which the token must not be accepted, used to pre-issue a token that only becomes valid later. Same…iat— Issued At: Unix epoch seconds when the token was created. Useful for rejecting implausibly old or future-dated tokens and, in OIDC flows, for bounding…jti— JWT ID: A unique, case-sensitive identifier for this specific token, used to support replay-detection via a seen-jti cache or to correlate a token…alg— Algorithm: On a JWS this is the signing algorithm (e.g. HS256, RS256, EdDSA); on a JWE it is the key-management algorithm used to establish the…typ— Type: Media type of the whole token, letting an application distinguish this token from other JWT-shaped objects that might land on the same…cty— Content Type: Media type of the payload itself (not of the token). Set to JWT when the payload is another, nested JWT — the signal that this is a…kid— Key ID: An opaque hint for which key in a JWK Set (or key store) was used, matched by exact string equality. It is attacker-controlled and must be…jku— JWK Set URL: A URL the signer says a JWK Set can be fetched from. A verifier must never dereference this automatically from an untrusted token — doing…jwk— JSON Web Key: A public key embedded directly in the header for verifying this same token's signature. Trusting it blindly is a classic bypass: an…x5u— X.509 URL: A URL pointing to a PEM-encoded X.509 certificate or chain for the signing key. Carries the same SSRF and trust risks as jku — never…x5c— X.509 Certificate Chain: The signing certificate chain, embedded as an array of standard base64 (not base64url) DER-encoded certificates. A verifier must validate…x5t— X.509 Certificate SHA-1 Thumbprint: A base64url-encoded SHA-1 digest of the DER-encoded signing certificate, used as a lookup hint similar to kid. SHA-1 is deprecated for…x5t#S256— X.509 Certificate SHA-256 Thumbprint: A base64url-encoded SHA-256 digest of the DER-encoded signing certificate — the modern, recommended replacement for the SHA-1-based x5t.crit— Critical: An array naming extension header parameters that a recipient must understand and process, or else reject the whole token. Registered…enc— Encryption Algorithm: The JWE content-encryption algorithm (e.g. A256GCM, A256CBC-HS512) applied with the content-encryption key. Like alg, it must be understood…zip— Compression Algorithm: Names a compression algorithm (only DEF/DEFLATE is registered) applied to the plaintext before encryption. Compressing attacker-influenced…epk— Ephemeral Public Key: The sender's ephemeral public key for ECDH-ES key agreement, present as a JWK object. The receiving library must validate that the supplied…apu— Agreement PartyUInfo: Base64url-encoded, application-supplied context information about the message originator, used as input to ECDH-ES key derivation (Concat…apv— Agreement PartyVInfo: Base64url-encoded, application-supplied context information about the message recipient, used alongside apu as ECDH-ES key-derivation input.p2s— PBES2 Salt Input: Base64url-encoded random salt input used, together with p2c, to derive the key-wrapping key in PBES2-based JWE (password-based encryption).…p2c— PBES2 Count: The PBKDF2 iteration count used for PBES2 password-based key derivation. Low values make offline password-guessing far cheaper; combined…iv— Initialization Vector: Base64url-encoded initialization vector used by AES-GCM key-wrapping algorithms (A*GCMKW) to wrap the content-encryption key. Reusing an IV…tag— Authentication Tag: Base64url-encoded GCM authentication tag produced when wrapping the content-encryption key with an A*GCMKW algorithm, carried alongside iv.…nonce— Nonce: A value the Relying Party generated and sent in the authentication request, echoed back unchanged in the ID token. It is OIDC's primary…auth_time— Authentication Time: Unix epoch seconds of the end-user's last authentication event at the OpenID Provider. Only meaningful to check when the RP specifically…acr— Authentication Context Class Reference: Indicates the authentication method/assurance level actually used (e.g. password-only vs. multi-factor), as a string agreed between OP and…amr— Authentication Methods References: An array of strings naming the authentication methods used (e.g. pwd, otp, mfa), values defined by the OpenID Provider's own convention…azp— Authorized Party: Identifies the OAuth client the token was issued to, needed only when aud contains more than one value. When present, the client should…at_hash— Access Token Hash: A hash of the access token issued alongside this ID token, letting the client confirm the two tokens came from the same response and…c_hash— Code Hash: A hash of the authorization code issued in the same response as this ID token, serving the same binding purpose as at_hash but for the code…sid— Session ID: Identifies the OpenID Provider's session the token was issued from, used mainly for OIDC front/back-channel logout to correlate a logout…client_id— Client ID: Identifies the OAuth client the access token was issued to — distinct from aud, which names the resource server(s) the token may be…scope— Scope: A single space-delimited string listing the OAuth scopes granted to this token (e.g. "read:items write:items"). Note the format difference…roles— Roles: A private/common-practice claim listing role names granted to the subject — not part of any single core RFC, but widely used by…groups— Groups: A private/common-practice claim listing directory or application group memberships for the subject, most often sourced from an upstream…entitlements— Entitlements: A private/common-practice claim listing fine-grained product or feature entitlements granted to the subject, distinct from coarser…cnf— Confirmation: Binds the token to a specific key the presenter must prove possession of (proof-of-possession), rather than the token being a plain bearer…act— Actor: Identifies the party actually acting on behalf of the token's subject in a delegation/impersonation scenario (RFC 8693 token exchange), as…may_act— Authorized Actor: Names a party that is pre-authorized to act on behalf of this token's subject via a future token-exchange request, i.e. it grants…tid— Tenant ID: The GUID of the Entra ID (Azure AD) tenant the token was issued from. Multi-tenant applications should check this against an allow-list of…oid— Object ID: The immutable GUID identifying the user or service principal within the tenant's directory, stable across app registrations and independent…upn— User Principal Name: The user's sign-in name in user@domain form. It is mutable (renamed on directory changes) and, per Microsoft's own guidance, increasingly…appid— Application ID: The client application's ID, present on Entra ID v1.0-format tokens; the equivalent claim on v2.0-format tokens is azp. Check the ver claim…appidacr— Application Authentication Context Class: Indicates how the client authenticated to obtain the token: 0 for a public client with no credential, 1 for a confidential client using a…idtyp— Identity Type: Set to "app" on access tokens issued for app-only (client-credentials, no signed-in user) scenarios; absent otherwise. A resource server…wids— Directory Role Template IDs: An array of GUIDs referencing built-in Entra ID directory roles (e.g. Global Administrator) held by the subject. This is jwt.io's own…xms_tcdt— Tenant Creation Time: Unix epoch seconds when the token's tenant was created. Occasionally used as a coarse signal to distinguish long-established organizations…preferred_username— Preferred Username: A human-readable, display-oriented username (technically a standard OIDC claim, but the one Entra ID emits in place of upn on v2.0 tokens).…ver— Token Version: Indicates whether this is a v1.0- or v2.0-format Entra ID token ("1.0" or "2.0"); the two versions differ in claim shapes (e.g. appid vs…org_id— Organization ID: The ID of the Auth0 Organization the token was issued for, present when Auth0's Organizations feature is used for B2B multi-tenant setups.…uid— User ID: Okta's internal, stable identifier for the authenticated user, distinct from sub (which may be a different, application-facing identifier…cid— Client ID: The OAuth client ID the Okta access token was issued to — Okta's equivalent of the generic client_id/azp claims used by other providers.scp— Scopes: An array of granted OAuth scope strings — Okta's array form of the same information the generic scope claim carries as a single…cognito:groups— Cognito Groups: An array of Cognito User Pool group names the user belongs to, present on both ID and access tokens. Group membership here reflects…cognito:username— Cognito Username: The user pool's internal username for the account. For federated (social/SAML) sign-ins this is often a provider-prefixed synthetic value…token_use— Token Use: Declares whether this Cognito token is an "id" token or an "access" token. A resource server must check this claim and reject the wrong…event_id— Event ID: Correlates the token with the specific Cognito authentication event (sign-in, refresh, etc.) that produced it, useful for audit-log…firebase— Firebase Metadata: An object carrying Firebase Authentication metadata about the sign-in, including identities (linked provider accounts) and sign_in_provider…sign_in_provider— Sign-in Provider: Names the identity provider used for this sign-in (e.g. "password", "google.com", "anonymous"). On a real Firebase ID token this appears…realm_access— Realm Access: An object with a roles array listing realm-level roles granted to the subject — roles that apply across every client in the Keycloak realm,…resource_access— Resource Access: An object keyed by client ID, where each entry holds a roles array of client-scoped roles granted to the subject for that specific client —…session_state— Session State: A legacy Keycloak session identifier predating the standard OIDC sid claim, which newer Keycloak versions emit alongside it. Prefer sid in…hd— Hosted Domain: The Google Workspace (formerly G Suite) domain the account belongs to, present only for Workspace-managed accounts. Applications that want…email_verified— Email Verified: A boolean (technically a standard OIDC claim, commonly seen on Google ID tokens) indicating whether Google has confirmed the user controls…picture— Profile Picture URL: A URL to the user's Google profile photo (also a standard OIDC claim). Purely for display — the URL can change over time and shouldn't be…