resource_access — Resource Access
Location: payload · Format: json · Vendor: Keycloak
An object keyed by client ID, where each entry holds a roles array of client-scoped roles granted to the subject for that specific client — finer-grained than the realm-wide roles in realm_access.
Defined in Keycloak server administration guide.
Decode a JWT and inspect its resource_access claim in the TokenPrism debugger — free, entirely in your browser.