aud — Audience

Location: payload · Format: array-or-string

Names the intended recipient(s) of the token — a single string or an array of strings. A verifier that fails to check its own identifier appears in this claim is exposed to substitution attacks (a token legitimately issued for service A gets replayed against service B); this is the single most commonly skipped check in real deployments.

Defined in RFC 7519 §4.1.3.

Decode a JWT and inspect its aud claim in the TokenPrism debugger — free, entirely in your browser.