sid — Session ID

Location: payload · Format: string

Identifies the OpenID Provider's session the token was issued from, used mainly for OIDC front/back-channel logout to correlate a logout notification with the right browser session. Several IdPs (Keycloak included) also emit this on access tokens for session tracking beyond pure OIDC logout.

Defined in OpenID Connect Front-Channel Logout 1.0.

Decode a JWT and inspect its sid claim in the TokenPrism debugger — free, entirely in your browser.