amr — Authentication Methods References

Location: payload · Format: array-or-string

An array of strings naming the authentication methods used (e.g. pwd, otp, mfa), values defined by the OpenID Provider's own convention rather than a fixed registry. Useful for step-up-auth decisions, but its values are provider-specific — don't assume the same string means the same thing across issuers.

Defined in OpenID Connect Core 1.0 §2.

Decode a JWT and inspect its amr claim in the TokenPrism debugger — free, entirely in your browser.