p2c — PBES2 Count
Location: header · Format: string
The PBKDF2 iteration count used for PBES2 password-based key derivation. Low values make offline password-guessing far cheaper; combined with RFC 8725's warning against human-memorable HMAC-style secrets, a very small p2c is itself a weak-configuration signal worth flagging.
Defined in RFC 7518 §4.8.1.2.
Decode a JWT and inspect its p2c claim in the TokenPrism debugger — free, entirely in your browser.