cnf — Confirmation
Location: payload · Format: json
Binds the token to a specific key the presenter must prove possession of (proof-of-possession), rather than the token being a plain bearer credential — commonly holds a jwk or jkt (JWK thumbprint) member. A resource server must actually verify possession of the confirmed key on each use; simply reading the claim without checking the proof provides no security benefit.
Defined in RFC 7800 §3.
Decode a JWT and inspect its cnf claim in the TokenPrism debugger — free, entirely in your browser.