jwk — JSON Web Key

Location: header · Format: json

A public key embedded directly in the header for verifying this same token's signature. Trusting it blindly is a classic bypass: an attacker can generate their own keypair, sign a forged token with the private half, and embed the matching public key here — a verifier must ignore it unless that exact key is independently pinned elsewhere.

Defined in RFC 7515 §4.1.3.

Decode a JWT and inspect its jwk claim in the TokenPrism debugger — free, entirely in your browser.