tag — Authentication Tag
Location: header · Format: string
Base64url-encoded GCM authentication tag produced when wrapping the content-encryption key with an A*GCMKW algorithm, carried alongside iv. Decryption must reject on any tag mismatch without leaking which part of the check failed, to avoid a padding/tag oracle.
Defined in RFC 7518 §4.7.1.2.
Decode a JWT and inspect its tag claim in the TokenPrism debugger — free, entirely in your browser.