x5c — X.509 Certificate Chain

Location: header · Format: json

The signing certificate chain, embedded as an array of standard base64 (not base64url) DER-encoded certificates. A verifier must validate the whole chain up to a trusted root before use — trusting the leaf certificate on its own is the same class of bug as trusting an embedded jwk.

Defined in RFC 7515 §4.1.6.

Decode a JWT and inspect its x5c claim in the TokenPrism debugger — free, entirely in your browser.