epk — Ephemeral Public Key

Location: header · Format: json

The sender's ephemeral public key for ECDH-ES key agreement, present as a JWK object. The receiving library must validate that the supplied point actually lies on the expected curve before using it in the key-agreement computation — skipping that check enables an invalid-curve attack that can leak bits of the recipient's static private key.

Defined in RFC 7518 §4.6.1.1.

Decode a JWT and inspect its epk claim in the TokenPrism debugger — free, entirely in your browser.