jwk — JSON Web Key
Location: header · Format: json
A public key embedded directly in the header for verifying this same token's signature. Trusting it blindly is a classic bypass: an attacker can generate their own keypair, sign a forged token with the private half, and embed the matching public key here — a verifier must ignore it unless that exact key is independently pinned elsewhere.
Defined in RFC 7515 §4.1.3.
Decode a JWT and inspect its jwk claim in the TokenPrism debugger — free, entirely in your browser.