at_hash — Access Token Hash
Location: payload · Format: string
A hash of the access token issued alongside this ID token, letting the client confirm the two tokens came from the same response and haven't been mixed up or substituted. Only checked when both tokens are present in the same flow (e.g. hybrid/implicit flows).
Defined in OpenID Connect Core 1.0 §3.1.3.6.
Decode a JWT and inspect its at_hash claim in the TokenPrism debugger — free, entirely in your browser.