groups — Groups
Location: payload · Format: array-or-string
A private/common-practice claim listing directory or application group memberships for the subject, most often sourced from an upstream directory (LDAP/Entra ID/etc.). Group membership claims can be large; some IdPs cap or omit this claim for users in very many groups, so absence doesn't necessarily mean "no groups."
Decode a JWT and inspect its groups claim in the TokenPrism debugger — free, entirely in your browser.