kid — Key ID

Location: header · Format: string

An opaque hint for which key in a JWK Set (or key store) was used, matched by exact string equality. It is attacker-controlled and must be treated purely as an opaque lookup key — using it to build a file path or SQL query without strict allow-listing is a well-known injection/path-traversal vector.

Defined in RFC 7515 §4.1.4.

Decode a JWT and inspect its kid claim in the TokenPrism debugger — free, entirely in your browser.