typ — Type
Location: header · Format: string
Media type of the whole token, letting an application distinguish this token from other JWT-shaped objects that might land on the same validation endpoint (e.g. at+jwt for OAuth access tokens). Matching is case-insensitive and the application/ prefix is optional; some identity providers use non-standard values here (Keycloak, for instance, sets it to "Bearer" for access tokens), so don't assume it is always exactly "JWT".
Defined in RFC 7515 §4.1.9.
Decode a JWT and inspect its typ claim in the TokenPrism debugger — free, entirely in your browser.