JWT Claims Reference

Registered claims, common custom claims, and validation tips for JSON Web Tokens.

Registered Claims

Key / CodeDescription
issIssuer — who issued the token.
subSubject — who the token is about.
audAudience — intended recipients.
expExpiration time (Unix).
nbfNot before time.
iatIssued at time.
jtiJWT ID — unique token identifier.

Common Custom Claims

Key / CodeDescription
roleUser role or permissions.
scopeSpace-delimited permissions.
tenant_idMulti-tenant identifier.

Validation Checklist

Always validate signature, issuer, audience, and expiration. Reject tokens using none or unexpected algorithms.

Knowledge is power.