sub — Subject

Location: payload · Format: string

Identifies the principal the token is about — usually the authenticated user or service. Must be unique within the issuer's namespace (or globally unique); many identity providers use an opaque internal ID here rather than an email or username, since those can change over the life of an account.

Defined in RFC 7519 §4.1.2.

Decode a JWT and inspect its sub claim in the TokenPrism debugger — free, entirely in your browser.