Security · Developer Guide
How to Decode and Debug JWT Tokens
A readable token is not a trusted token. Use decoding to investigate a login problem, then let the application verify the signature and claims before granting access.
What is a JWT?
A common signed compact JWT has three dot-separated segments: a header, a payload, and a signature. The first two use Base64URL-encoded JSON. Encryption uses a different representation; the decoder here accepts three non-empty segments, not encrypted five-segment tokens.
How to inspect a token
- Paste the token itself, without the Authorization: Bearer prefix, into JWT Decoder.
- Inspect header fields such as alg and kid to identify the intended algorithm and key lookup. Treat those fields as untrusted input.
- Inspect payload fields such as iss, aud, sub, exp, and nbf against the application's documented expectations.
- Check the server clock and configured clock tolerance. The local expiration checker uses your device clock and does not verify a signature.
Example: diagnose an expiry mismatch
Suppose a decoded payload contains the following claims. The exp value describes 2025-01-01T01:00:00Z. A milliseconds-based comparison with that raw number would make the token appear expired far too early.
{
"sub": "demo-user",
"aud": "example-api",
"exp": 1735693200
}
JavaScript comparison:
Date.now() / 1000 >= payload.expCommon mistakes
- Using a standard Base64 decoder on the whole token: split the segments and account for Base64URL's alphabet and padding rules. The JWT Decoder handles this for you.
- Treating an unexpired token as valid: the issuer, audience, signature, and other application rules still need checking.
- Assuming decoded fields are secret: signed payloads can be read by anyone who possesses the token.
- Changing exp locally: editing a claim changes the signed data and invalidates the original signature.
Practical use cases
When one service rejects a token accepted by another, compare their expected issuer and audience, then inspect the selected verification key and algorithm on the server. When expiry differs between environments, compare clocks and units before changing token lifetimes.
Security considerations
Small Tools displays decoded claims and explicitly reports that the signature is not verified. Never use its output as an authorization decision. Use a maintained JWT verification library in the application, with expected algorithms, issuer, and audience configured by trusted application settings.
Processing is local to your browser. A real access token may still grant access if copied into a chat, issue, screenshot, or clipboard history. Prefer fabricated or expired diagnostic tokens and redact sensitive claims before sharing.
Related tools
- JWT Decoder — Decode a JWT header and payload without verifying its signature.
- JWT Header Decoder — Decode the protected header segment of a JWT locally.
- JWT Expiration Checker — Read a JWT exp claim and compare it with the current time.
- Unix Timestamp Converter — Convert Unix timestamps in seconds or milliseconds to readable dates.