Skip to content

JWT decoder

Debug authentication problems by reading what a token actually says, in a tool that is explicit about what it does not prove.

The signature is not verified. This tool only decodes the structure. A decoded token proves nothing about who issued it or whether it is still valid for your API.

Algorithm (alg)HS256
Type (typ)JWT
Signature partpresent (not checked)
Expiry—
Issuer (iss)https://auth.example.com
Subject (sub)user_42
Audience (aud)api
Issued at (iat)2023-11-14T22:13:20.000Z
Expires (exp)2027-01-15T08:00:00.000Z

Header

{
  "alg": "HS256",
  "typ": "JWT"
}

Payload

{
  "iss": "https://auth.example.com",
  "sub": "user_42",
  "aud": "api",
  "iat": 1700000000,
  "exp": 1800000000,
  "scope": "monitors:read"
}

Decoding happens in your browser; the token is not sent anywhere. Avoid pasting production tokens into any website, including this one.

Monitor authenticated API flows with transaction checks. Free for 5 monitors, no credit card.

Start monitoring

How it measures

  • The three base64url parts are split and the first two decoded as JSON (RFC 7519).
  • exp, nbf and iat are rendered as ISO dates and compared with your clock.

Limits

  • The signature is never checked, so nothing here proves a token is genuine or accepted by your API.
  • Encrypted tokens (JWE, five parts) are not supported.

Troubleshooting

API rejects a token that looks valid here
Validity depends on the signature, the key, the audience and issuer the server expects, and clock skew. This tool cannot see those.

Related tools