Skip to content

JsonWebTokenPayload Class

Represents the payload part of a JSON Web Token (JWT), containing the claims or statements about the subject.

C#
public class JsonWebTokenPayload

Inheritance System.Object → JsonWebTokenPayload

Remarks

The JWT payload is a JSON object that contains the claims transmitted by the token. Standard claims such as issuer, subject, expiration time, and more can be included, as well as additional claims as needed. This class provides a convenient way to work with the payload, allowing for easy access and modification of claims.

Constructors

JsonWebTokenPayload(JsonObject) Constructor

Represents the payload part of a JSON Web Token (JWT), containing the claims or statements about the subject.

C#
public JsonWebTokenPayload(System.Text.Json.Nodes.JsonObject json);

Parameters

json System.Text.Json.Nodes.JsonObject

Remarks

The JWT payload is a JSON object that contains the claims transmitted by the token. Standard claims such as issuer, subject, expiration time, and more can be included, as well as additional claims as needed. This class provides a convenient way to work with the payload, allowing for easy access and modification of claims.

Properties

JsonWebTokenPayload.AccessTokenHash Property

A digest binding this ID token to the access token issued alongside it, per OpenID Connect Core section 3.1.3.6.

C#
public string? AccessTokenHash { get; set; }

Property Value

System.String

Remarks

Read by a relying party to confirm that the access token it holds is the one this ID token was issued with. Without that binding an attacker who can substitute an access token gets an identity assertion about one user paired with authority belonging to another.

JsonWebTokenPayload.Audiences Property

The intended audiences for the JWT.

C#
public System.Collections.Generic.IEnumerable<string> Audiences { get; set; }

Property Value

System.Collections.Generic.IEnumerable<System.String>

JsonWebTokenPayload.AuthContextClassRef Property

Represents the Authentication Context Class Reference (ACR) indicating the authentication context achieved during authentication.

C#
public string? AuthContextClassRef { get; set; }

Property Value

System.String

Remarks

In federated and multi-tenant environments, the acr claim helps assert that the user was authenticated under a specific assurance level (e.g., "urn:openbanking:psd2:sca" or "loa3").

This is particularly important for applications that integrate with external identity providers, regulatory domains (such as finance or healthcare), or environments where different tenants require varying levels of authentication rigor. The ACR value enables relying parties to make access decisions based on agreed-upon trust frameworks and security profiles.

JsonWebTokenPayload.AuthenticationMethodReferences Property

A list of authentication methods used to authenticate the subject, represented as Authentication Method Reference (AMR) values.

C#
public System.Collections.Generic.IEnumerable<string>? AuthenticationMethodReferences { get; set; }

Property Value

System.Collections.Generic.IEnumerable<System.String>

Remarks

In multi-tenant and federated identity systems, this claim helps relying parties understand the authentication strength applied to a user session.

Each value in the list corresponds to a specific method used during authentication, such as "pwd" (password), "mfa" (multi-factor authentication), "otp" (one-time password), or "fido" (FIDO-based authentication).

These values support policy enforcement at the tenant level, allowing services to require particular authentication methods (e.g., tenants enforcing MFA) or to provide differentiated access based on authentication robustness.

JsonWebTokenPayload.AuthenticationTime Property

Represents the time when the authentication occurred, facilitating checks against token freshness and replay attacks.

C#
public System.Nullable<System.DateTimeOffset> AuthenticationTime { get; set; }

Property Value

System.Nullable<System.DateTimeOffset>

Remarks

Storing the authentication time is critical for applications requiring a high level of assurance regarding the moment a user was authenticated, allowing for precise control over session validity and user authentication status.

JsonWebTokenPayload.AuthorizationDetails Property

The RFC 9396 authorization_details claim as a sequence of typed wrappers over the underlying System.Text.Json.Nodes.JsonArray stored at Json[authorization_details]. Each wrapper shares its System.Text.Json.Nodes.JsonNode reference with the corresponding array element - read-through is byte-exact, and property setters on a wrapper mutate the underlying claim in place. Assigning a new sequence rebuilds the raw array via ToRawJsonArray(this IEnumerable<AuthorizationDetail>), deep-cloning each entry's Json to detach parent ownership; assigning null removes the claim. For direct raw access bypass this accessor and use the Json indexer at IanaClaimTypes.AuthorizationDetails.

C#
public System.Collections.Generic.IEnumerable<Abblix.Jwt.AuthorizationDetail>? AuthorizationDetails { get; set; }

Property Value

System.Collections.Generic.IEnumerable<AuthorizationDetail>

JsonWebTokenPayload.AuthorizedParty Property

The authorized party (azp): the party the token was issued to. OpenID Connect Core 1.0 section 2 defines it in one sentence - "OPTIONAL. Authorized party - the party to which the ID Token was issued. If present, it MUST contain the OAuth 2.0 Client ID of this party." So the claim is optional, and the only obligation attaches to its value.

C#
public string? AuthorizedParty { get; set; }

Property Value

System.String

Remarks

This described the claim as mandated, and as keyed to the issuer, until 2026-07-20. Both were wrong, and the second inverts what the claim is for: azp names the recipient, not the sender. The conditions the old text carried - a single audience differing from something, or more than one audience - come from wording that errata set 2 replaced. A recipient's duty is correspondingly weak: section 3.1.3.7 step 4 says a client using extensions that produce azp "SHOULD validate the azp value as specified by those extensions", and step 5 that this "MAY include that when an azp Claim is present, the Client SHOULD verify that its client_id is the Claim Value". Nothing here is a MUST, and a validator that rejects on a missing azp will refuse conformant issuers.

JsonWebTokenPayload.ClientId Property

The client ID for which the JWT was issued, identifying the client application in OAuth 2.0 and OpenID Connect flows.

C#
public string? ClientId { get; set; }

Property Value

System.String

Remarks

This property is crucial in scenarios where the JWT is used to convey or assert the identity of a client application to the authorization server or resource server.

JsonWebTokenPayload.CodeHash Property

A digest binding this ID token to the authorization code issued alongside it, per OpenID Connect Core section 3.3.2.11.

C#
public string? CodeHash { get; set; }

Property Value

System.String

Remarks

Present in the hybrid flow, where the ID token arrives through the front channel before the code is redeemed. It is what lets the relying party detect a code swapped in transit, since the swapped code would not match the digest in a token it cannot forge.

JsonWebTokenPayload.Confirmation Property

The proof-of-possession confirmation object (RFC 7800 §3.1 cnf) bound to this JWT. Carries each binding the token holds - cnf.x5t#S256 for mTLS-bound tokens (RFC 8705 §3.1) and cnf.jkt for DPoP-bound tokens (RFC 9449 §6.1) - behind typed accessors. Assignment writes the wrapped System.Text.Json.Nodes.JsonObject as the cnf claim; assigning null removes the claim.

C#
public Abblix.Jwt.JsonWebTokenConfirmation? Confirmation { get; set; }

Property Value

JsonWebTokenConfirmation

JsonWebTokenPayload.DPoPAccessTokenHash Property

The access-token hash bound by a DPoP proof when one accompanies an access token (RFC 9449 §4.2 ath): Base64Url(SHA-256(access_token)).

C#
public string? DPoPAccessTokenHash { get; set; }

Property Value

System.String

JsonWebTokenPayload.DPoPHttpMethod Property

The HTTP method bound by a DPoP proof (RFC 9449 §4.2 htm). Compared byte-exact against the current request method on the server side.

C#
public string? DPoPHttpMethod { get; set; }

Property Value

System.String

JsonWebTokenPayload.DPoPHttpUri Property

The HTTP URI bound by a DPoP proof (RFC 9449 §4.2 htu). Returned as the raw claim string so callers keep the three-way "missing / unparseable / mismatched" distinction; parsing into a System.Uri belongs to the comparison step.

C#
public string? DPoPHttpUri { get; set; }

Property Value

System.String

JsonWebTokenPayload.Email Property

The email address of the subject.

C#
public string? Email { get; set; }

Property Value

System.String

Remarks

When the subject uses external authentication (Google, Microsoft, etc.) or authenticates via email verification, this property contains the exact email used during authentication, ensuring the email claim in ID tokens reflects the authentication method rather than the primary email from the user's profile.

JsonWebTokenPayload.EmailVerified Property

Indicates whether the email address has been verified.

C#
public System.Nullable<bool> EmailVerified { get; set; }

Property Value

System.Nullable<System.Boolean>

Remarks

For external providers that verify emails or when email verification has been completed through challenge flows, this value is set to true. This is used in the email_verified claim in ID tokens.

JsonWebTokenPayload.ExpiresAt Property

The expiration time on or after which the JWT must not be accepted for processing, represented as a Unix timestamp.

C#
public System.Nullable<System.DateTimeOffset> ExpiresAt { get; set; }

Property Value

System.Nullable<System.DateTimeOffset>

JsonWebTokenPayload.GrantId Property

Identifies the authorization grant this refresh token belongs to, binding it to the lineage of every refresh token derived from the same grant. A first-issued token starts a new grant; each rotation carries the value forward, so a detected replay can revoke the whole family in one registry write (RFC 9700 Section 4.14.2).

C#
public string? GrantId { get; set; }

Property Value

System.String

Remarks

Present only on refresh tokens (rt+jwt); absent (null) on all other token types, which leaves the family cascade in the token-status validator inert for them.

JsonWebTokenPayload.IdentityProvider Property

Identifies the identity provider that authenticated the end user, useful in federated identity scenarios.

C#
public string? IdentityProvider { get; set; }

Property Value

System.String

Remarks

This claim is particularly relevant in systems that support multiple identity providers, helping to trace the origin of the authentication and ensuring that the JWT can be validated appropriately.

JsonWebTokenPayload.IssuedAt Property

The time at which the JWT was issued, represented as a Unix timestamp.

C#
public System.Nullable<System.DateTimeOffset> IssuedAt { get; set; }

Property Value

System.Nullable<System.DateTimeOffset>

JsonWebTokenPayload.Issuer Property

The issuer of the JWT.

C#
public string? Issuer { get; set; }

Property Value

System.String

JsonWebTokenPayload.Json Property

The underlying mutable JSON object backing the strongly-typed accessors on this payload. Use this for custom claims that are not exposed as named properties on this class.

C#
public System.Text.Json.Nodes.JsonObject Json { get; }

Property Value

System.Text.Json.Nodes.JsonObject

JsonWebTokenPayload.JwtId Property

The unique identifier of the JWT.

C#
public string? JwtId { get; set; }

Property Value

System.String

JsonWebTokenPayload.Nonce Property

A value used to associate a client session with an ID token, mitigating replay attacks.

C#
public string? Nonce { get; set; }

Property Value

System.String

JsonWebTokenPayload.NotBefore Property

The time before which the JWT must not be accepted for processing, represented as a Unix timestamp.

C#
public System.Nullable<System.DateTimeOffset> NotBefore { get; set; }

Property Value

System.Nullable<System.DateTimeOffset>

JsonWebTokenPayload.Scope Property

The scope of access granted by the JWT. Scope is typically a space-separated list of permissions or access levels and is not part of the standard JWT claims.

C#
public System.Collections.Generic.IEnumerable<string> Scope { get; set; }

Property Value

System.Collections.Generic.IEnumerable<System.String>

Remarks

The 'scope' claim is often used in OAuth 2.0 and OpenID Connect contexts to specify the extent of access granted by the token. Each value in the list represents a specific permission or access level granted to the token bearer. This property ensures that the scope is represented appropriately as either a single value or an array of values.

JsonWebTokenPayload.SessionId Property

The session ID associated with the JWT, typically used to manage session state across applications.

C#
public string? SessionId { get; set; }

Property Value

System.String

Remarks

The session ID can link the JWT to a specific session for the user, allowing for effective session management and security controls.

JsonWebTokenPayload.Subject Property

The subject of the JWT. The subject typically represents the principal that is the focus of the JWT, often a user identifier.

C#
public string? Subject { get; set; }

Property Value

System.String

Remarks

The 'sub' (subject) claim is a standard claim in JWTs used to uniquely identify the principal, usually in the context of authentication or user identity. It is commonly a user ID or username.

JsonWebTokenPayload.this[string] Property

Indexer to get or set claim values in the payload using the claim name.

C#
public System.Text.Json.Nodes.JsonNode? this[string name] { get; set; }

Parameters

name System.String

The name of the claim.

Property Value

System.Text.Json.Nodes.JsonNode

Methods

JsonWebTokenPayload.TryReadTimestamp(string, Nullable<DateTimeOffset>, string) Method

Reads one timestamp claim by name, answering false with the reason instead of throwing where it cannot be read.

C#
public bool TryReadTimestamp(string claim, out System.Nullable<System.DateTimeOffset> value, out string? whyUnreadable);

Parameters

claim System.String

The claim name, one of the registered timestamp claims or any other claim holding a NumericDate.

value System.Nullable<System.DateTimeOffset>

The claim's value, or null where the token carries none.

whyUnreadable System.String

Which claim could not be read and what it held, or null where it was read.

Returns

System.Boolean
True where the claim was read, or is absent.

Remarks

For a caller that judges one claim and must say nothing about the others: a DPoP proof is refused on its iat alone, and a refusal naming a claim it never looked at would be wrong twice over.

JsonWebTokenPayload.TryReadTimestamps(Nullable<DateTimeOffset>, Nullable<DateTimeOffset>, Nullable<DateTimeOffset>, string) Method

Reads the three timestamp claims at once, answering false with the reason instead of throwing where one of them cannot be read.

C#
public bool TryReadTimestamps(out System.Nullable<System.DateTimeOffset> notBefore, out System.Nullable<System.DateTimeOffset> expiresAt, out System.Nullable<System.DateTimeOffset> issuedAt, out string? whyUnreadable);

Parameters

notBefore System.Nullable<System.DateTimeOffset>

The nbf claim, or null where the token carries none.

expiresAt System.Nullable<System.DateTimeOffset>

The exp claim, or null where the token carries none.

issuedAt System.Nullable<System.DateTimeOffset>

The iat claim, or null where the token carries none.

whyUnreadable System.String

Which claim could not be read and what it held, or null where all three were read.

Returns

System.Boolean
True where every timestamp the token carries was read.

Remarks

The typed accessors throw on a value that is not a NumericDate - a string, an object, a number outside the range System.DateTimeOffset can hold - because a caller asking for a timestamp has nowhere to put "the token lied". A validator does: a claim it cannot read is a refusal of the token, never an exception out of the request. This is the read a validator makes, and it names the claim, since the sender can fix only the one it is told about.