auth_time — Authentication Time
Location: payload · Format: timestamp
Unix epoch seconds of the end-user's last authentication event at the OpenID Provider. Only meaningful to check when the RP specifically requested it (e.g. via max_age), typically to force re-authentication for sensitive actions if the session is too old.
Defined in OpenID Connect Core 1.0 §2.
Decode a JWT and inspect its auth_time claim in the TokenPrism debugger — free, entirely in your browser.