cty — Content Type
Location: header · Format: string
Media type of the payload itself (not of the token). Set to JWT when the payload is another, nested JWT — the signal that this is a nested-JWT structure whose inner token must be independently, fully re-validated rather than trusted because the outer layer verified.
Defined in RFC 7515 §4.1.10.
Decode a JWT and inspect its cty claim in the TokenPrism debugger — free, entirely in your browser.