zip — Compression Algorithm

Location: header · Format: string

Names a compression algorithm (only DEF/DEFLATE is registered) applied to the plaintext before encryption. Compressing attacker-influenced plaintext before encrypting it can leak information through ciphertext length (a CRIME/BREACH-style oracle), and decompressing an untrusted ciphertext without a size cap is a zip-bomb denial-of-service vector — most implementations should avoid or tightly bound this.

Defined in RFC 7516 §4.1.3.

Decode a JWT and inspect its zip claim in the TokenPrism debugger — free, entirely in your browser.