idtyp — Identity Type
Location: payload · Vendor: Microsoft Entra
Set to "app" on access tokens issued for app-only (client-credentials, no signed-in user) scenarios; absent otherwise. A resource server that expects a delegated (user) token should explicitly reject tokens carrying idtyp: "app" rather than assume the presence of an oid/sub implies a real user.
Defined in Microsoft identity platform token reference.
Decode a JWT and inspect its idtyp claim in the TokenPrism debugger — free, entirely in your browser.