jku — JWK Set URL

Location: header · Format: string

A URL the signer says a JWK Set can be fetched from. A verifier must never dereference this automatically from an untrusted token — doing so is both an SSRF vector and lets an attacker point verification at a JWK Set they control; only pre-registered, allow-listed URLs should ever be fetched, and only on explicit user/application action.

Defined in RFC 7515 §4.1.2.

Decode a JWT and inspect its jku claim in the TokenPrism debugger — free, entirely in your browser.