kid — Key ID
Location: header · Format: string
An opaque hint for which key in a JWK Set (or key store) was used, matched by exact string equality. It is attacker-controlled and must be treated purely as an opaque lookup key — using it to build a file path or SQL query without strict allow-listing is a well-known injection/path-traversal vector.
Defined in RFC 7515 §4.1.4.
Decode a JWT and inspect its kid claim in the TokenPrism debugger — free, entirely in your browser.