>_devtools

OIDC Claims Reference & ID Token Checker

Look up standard OpenID Connect claims and check an ID token's iss, aud, azp, exp, nonce, auth_time, at_hash, and c_hash against what you expect.

What this does

Two things for OpenID Connect work. The reference lists the claims you meet in ID tokens and in the standard user profile, with their types and the scope that releases them. The checker takes an ID token and the values you expect, and runs the validation steps of OpenID Connect Core section 3.1.3.7 that concern claims.

What is checked

  • iss equals the expected issuer; sub is present.
  • aud contains your client_id; with several audiences, azp is present and equals it.
  • exp is in the future and iat is present, with the time you choose to evaluate at (default: now).
  • nonce equals the one you sent.
  • With max_age, auth_time exists and is recent enough.
  • With an access token or authorization code, at_hash or c_hash is recomputed: the left half of the SHA-2 hash that matches the token's signing algorithm, base64url encoded.

This page does not verify the signature. Do that first, with the issuer's keys, in the JWT decoder. A claim check on an unverified token only tells you what it says, not whether to trust it.

Example

"Load example" uses the ID token and access token from the OpenID Connect Core specification, evaluated at a time inside its validity window, so every check passes including at_hash.

Privacy

Tokens are checked in your browser and never leave it.