JWT声明名称是否区分大小写?含aud与AUD的Payload是否等效?
Great questions—let's unpack these based on the official JWT spec (RFC 7519) and real-world implementation practices:
1. Are JWT claim names case-sensitive?
- Short answer: Yes, they are, according to the strict JWT specification.
- This rule applies to both registered standard claims (like
iss,sub,aud,exp) and any custom claims you define. For example, a claim named"exp"(the standard expiration time field) and one named"EXP"will be treated as two completely separate claims by a spec-compliant validator. - That said, some JWT libraries offer lenient, non-standard handling that ignores case differences to work with poorly formatted tokens. But relying on this is risky—sticking to consistent lowercase for standard claims is the safest way to avoid compatibility issues.
2. Are the Payloads { "aud": ["aud1", "aud2"] } and { "AUD": ["aud1", "aud2"] } equivalent?
- Short answer: No, they are not equivalent in a spec-compliant system.
- The lowercase
"aud"is a registered standard claim designed to identify the token's intended audience(s). A proper validator will check this field against your application's expected audience to ensure the token is meant for you. - The uppercase
"AUD"is just a custom claim with no special meaning under the JWT spec. A strict validator won't recognize it as the audience claim, so it won't be used for audience validation. - Again, some libraries might bend the rules here, but this isn't part of the official standard—using lowercase
audis the only reliable way to ensure proper audience checks.
内容的提问来源于stack exchange,提问作者Maciej Treder
相关产品推荐
相关产品推荐

