token_use — Token Use

Location: payload · Vendor: AWS Cognito

Declares whether this Cognito token is an "id" token or an "access" token. A resource server must check this claim and reject the wrong kind outright — accepting an ID token where an access token is expected (or vice versa) is exactly the cross-token-type confusion RFC 8725 warns about.

Defined in Amazon Cognito user pool tokens.

Decode a JWT and inspect its token_use claim in the TokenPrism debugger — free, entirely in your browser.