cnf — Confirmation

Location: payload · Format: json

Binds the token to a specific key the presenter must prove possession of (proof-of-possession), rather than the token being a plain bearer credential — commonly holds a jwk or jkt (JWK thumbprint) member. A resource server must actually verify possession of the confirmed key on each use; simply reading the claim without checking the proof provides no security benefit.

Defined in RFC 7800 §3.

Decode a JWT and inspect its cnf claim in the TokenPrism debugger — free, entirely in your browser.