Learn › JWT claims reference

x5u — X.509 URL

Location: header · Format: string

A URL pointing to a PEM-encoded X.509 certificate or chain for the signing key. Carries the same SSRF and trust risks as jku — never fetched automatically from an untrusted token.

Defined in RFC 7515 §4.1.5.

Decode a JWT and inspect its x5u claim in the TokenPrism debugger — free, entirely in your browser.