appidacr — Application Authentication Context Class

Location: payload · Vendor: Microsoft Entra

Indicates how the client authenticated to obtain the token: 0 for a public client with no credential, 1 for a confidential client using a shared secret, 2 for a confidential client using a certificate or signed client assertion. Useful for flagging tokens issued to weakly-authenticated clients.

Defined in Microsoft identity platform token reference.

Decode a JWT and inspect its appidacr claim in the TokenPrism debugger — free, entirely in your browser.