zip — Compression Algorithm
Location: header · Format: string
Names a compression algorithm (only DEF/DEFLATE is registered) applied to the plaintext before encryption. Compressing attacker-influenced plaintext before encrypting it can leak information through ciphertext length (a CRIME/BREACH-style oracle), and decompressing an untrusted ciphertext without a size cap is a zip-bomb denial-of-service vector — most implementations should avoid or tightly bound this.
Defined in RFC 7516 §4.1.3.
Decode a JWT and inspect its zip claim in the TokenPrism debugger — free, entirely in your browser.