Learn › JWT claims reference

tag — Authentication Tag

Location: header · Format: string

Base64url-encoded GCM authentication tag produced when wrapping the content-encryption key with an A*GCMKW algorithm, carried alongside iv. Decryption must reject on any tag mismatch without leaking which part of the check failed, to avoid a padding/tag oracle.

Defined in RFC 7518 §4.7.1.2.

Decode a JWT and inspect its tag claim in the TokenPrism debugger — free, entirely in your browser.