may_act — Authorized Actor

Location: payload · Format: json

Names a party that is pre-authorized to act on behalf of this token's subject via a future token-exchange request, i.e. it grants delegation rather than recording that delegation already happened (which is what act does). Present on the original token that permits the exchange, not on the exchanged/delegated token itself.

Defined in RFC 8693 §4.4.

Decode a JWT and inspect its may_act claim in the TokenPrism debugger — free, entirely in your browser.