What this does
Two things for OpenID Connect work. The reference lists the claims you meet in ID tokens and in the standard user profile, with their types and the scope that releases them. The checker takes an ID token and the values you expect, and runs the validation steps of OpenID Connect Core section 3.1.3.7 that concern claims.
What is checked
issequals the expected issuer;subis present.audcontains yourclient_id; with several audiences,azpis present and equals it.expis in the future andiatis present, with the time you choose to evaluate at (default: now).nonceequals the one you sent.- With
max_age,auth_timeexists and is recent enough. - With an access token or authorization code,
at_hashorc_hashis recomputed: the left half of the SHA-2 hash that matches the token's signing algorithm, base64url encoded.
This page does not verify the signature. Do that first, with the issuer's keys, in the JWT decoder. A claim check on an unverified token only tells you what it says, not whether to trust it.
Example
"Load example" uses the ID token and access token from the OpenID Connect Core specification, evaluated at a time inside its validity window, so every check passes including at_hash.
Privacy
Tokens are checked in your browser and never leave it.