groups — Groups

Location: payload · Format: array-or-string

A private/common-practice claim listing directory or application group memberships for the subject, most often sourced from an upstream directory (LDAP/Entra ID/etc.). Group membership claims can be large; some IdPs cap or omit this claim for users in very many groups, so absence doesn't necessarily mean "no groups."

Decode a JWT and inspect its groups claim in the TokenPrism debugger — free, entirely in your browser.