JWT decoder
Debug authentication problems by reading what a token actually says, in a tool that is explicit about what it does not prove.
The signature is not verified. This tool only decodes the structure. A decoded token proves nothing about who issued it or whether it is still valid for your API.
| Algorithm (alg) | HS256 |
|---|---|
| Type (typ) | JWT |
| Signature part | present (not checked) |
| Expiry | — |
| Issuer (iss) | https://auth.example.com |
| Subject (sub) | user_42 |
| Audience (aud) | api |
| Issued at (iat) | 2023-11-14T22:13:20.000Z |
| Expires (exp) | 2027-01-15T08:00:00.000Z |
Header
{
"alg": "HS256",
"typ": "JWT"
}Payload
{
"iss": "https://auth.example.com",
"sub": "user_42",
"aud": "api",
"iat": 1700000000,
"exp": 1800000000,
"scope": "monitors:read"
}Decoding happens in your browser; the token is not sent anywhere. Avoid pasting production tokens into any website, including this one.
Monitor authenticated API flows with transaction checks. Free for 5 monitors, no credit card.
Start monitoringHow it measures
- The three base64url parts are split and the first two decoded as JSON (RFC 7519).
- exp, nbf and iat are rendered as ISO dates and compared with your clock.
Limits
- The signature is never checked, so nothing here proves a token is genuine or accepted by your API.
- Encrypted tokens (JWE, five parts) are not supported.
Troubleshooting
- API rejects a token that looks valid here
- Validity depends on the signature, the key, the audience and issuer the server expects, and clock skew. This tool cannot see those.