Additional custom or provider-specific claims.
Intended audience(s) of the token.
Optionalclient_Client ID of the application the token was issued to.
Expiration time of the token (Unix epoch seconds).
Time at which the token was issued (Unix epoch seconds).
Issuer identifier - the authorization server that issued the token.
OptionaljtiJWT ID (unique identifier for the token).
OptionalnbfNot-before time (Unix epoch seconds).
OptionalscopeOAuth scope associated with the token.
Subject identifier — uniquely identifies the authenticated user.
Claims contained in a validated OAuth 2.0 access token.