Claim (identity claim)
A single statement about a subject, such as its identifier, an attribute, or a token's issuer or expiry, asserted by an issuer and trusted only as far as the issuer and its signature are.
A claim is one piece of information asserted about a subject. RFC 7519, the JSON Web Token specification, defines it as a name and value pair, and a token’s payload is essentially a set of claims: who the subject is, who issued the token, which audience it is for, when it was issued and when it expires, plus attributes such as an email address, group membership or role. In SAML, the equivalent statements travel inside a SAML assertion.
The word also appears earlier in the access sequence: identification is a subject’s claim to an identity, which authentication then tests. A claim in a token is different in kind. It is not proof by itself; a relying party accepts it because the identity provider that issued it is trusted and its signature verifies. The relying party should also check the claims that limit the token, such as audience and expiry, before acting on the ones that grant access. An OpenID Connect ID token is a set of such claims.
Exam relevance: questions in this area tend to turn on trust. Candidates are expected to recognise that a claim is an assertion whose value depends on the issuer and the integrity protection around it, and to link claims to tokens and assertions in federated identity.