nonce — Nonce

Location: payload · Format: string

A value the Relying Party generated and sent in the authentication request, echoed back unchanged in the ID token. It is OIDC's primary replay defense for the authorization-code/implicit flows — the RP must verify it matches exactly whenever a nonce was sent, and reject the token otherwise.

Defined in OpenID Connect Core 1.0 §2.

Decode a JWT and inspect its nonce claim in the TokenPrism debugger — free, entirely in your browser.