OAuth oauth.net

JWT Profile for OAuth 2.0 Access Tokens

This profile defines a standard set of JWT claims for OAuth 2.0 access tokens, so resource servers from different vendors can validate tokens issued by any compliant authorization server without calling an introspection endpoint.

When to use this Use JWT access tokens when resource servers need to validate tokens locally without a network round-trip — important for performance at scale. The tradeoff: JWTs can't be revoked before they expire without adding back state. Keep access token lifetimes short (minutes, not hours) to limit the exposure window if a token is compromised.

RFC 9068 defines required claims — iss, exp, aud, sub, client_id, iat, jti — and a standard scope claim. The resource server validates the signature using the authorization server's public key (discoverable via server metadata), then checks aud to confirm the token was issued for this specific resource server.

Related specs

More resources