roles — Roles

Location: payload · Format: array-or-string

A private/common-practice claim listing role names granted to the subject — not part of any single core RFC, but widely used by authorization servers as a coarse-grained access-control signal alongside or instead of scope. Shape (string vs. array) varies by issuer, so treat it defensively when parsing.

Decode a JWT and inspect its roles claim in the TokenPrism debugger — free, entirely in your browser.