p2s — PBES2 Salt Input
Location: header · Format: string
Base64url-encoded random salt input used, together with p2c, to derive the key-wrapping key in PBES2-based JWE (password-based encryption). Must be freshly random per message — reusing it across tokens weakens the password-derived key.
Defined in RFC 7518 §4.8.1.1.
Decode a JWT and inspect its p2s claim in the TokenPrism debugger — free, entirely in your browser.