aud — Audience
Location: payload · Format: array-or-string
Names the intended recipient(s) of the token — a single string or an array of strings. A verifier that fails to check its own identifier appears in this claim is exposed to substitution attacks (a token legitimately issued for service A gets replayed against service B); this is the single most commonly skipped check in real deployments.
Defined in RFC 7519 §4.1.3.
Decode a JWT and inspect its aud claim in the TokenPrism debugger — free, entirely in your browser.