x5c — X.509 Certificate Chain
Location: header · Format: json
The signing certificate chain, embedded as an array of standard base64 (not base64url) DER-encoded certificates. A verifier must validate the whole chain up to a trusted root before use — trusting the leaf certificate on its own is the same class of bug as trusting an embedded jwk.
Defined in RFC 7515 §4.1.6.
Decode a JWT and inspect its x5c claim in the TokenPrism debugger — free, entirely in your browser.