thoughtasylumTOOLBOX Preview

What's inside this JWT?

A JSON Web Token (JWT) is the long eyJ… string that sign-in systems and APIs pass around to say who you are and what you may do. When a request fails with 401 Unauthorized, the token is the first thing to look at. These tools run in your browser and never put a token in a link, but treat a real token like a password all the same.

The token used here was made up for this guide:

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJhbGljZSIsImF1ZCI6ImFwaS5leGFtcGxlLmNvbSIsInNjb3BlIjoicmVhZCIsImlhdCI6MTc2NzIyNTYwMCwiZXhwIjoxNzY3MjI5MjAwfQ.c2lnbmF0dXJl

1. Make sure it’s a JWT

If you’re not sure what you’ve got, paste it into Identify first. Three Base64URL parts separated by dots, starting eyJ, is a JWT; the header’s algorithm (here HS256) is shown too.

2. Read the claims

Paste it into the JWT Decoder. A leading Bearer is ignored, so the whole Authorization header value works. The payload’s claims say who and what the token is for:

  • sub: who it was issued to (here alice).
  • aud: which service it’s meant for (api.example.com). A token sent to a different service is usually refused.
  • scope or scp: what it allows (read). A write request with a read-only token fails.
  • iat, nbf and exp: when it was issued, when it becomes valid, and when it expires.

3. Check the times

The decoder shows iat, nbf and exp in your local time with how long ago each was. This token was issued at midnight UTC on 1 January 2026 and expired an hour later, so it says This token has expired.

For a time elsewhere (a log line, another claim such as auth_time), paste the number into the Timestamp Converter: 1767229200 is 1 January 2026, 01:00 UTC. It tells seconds from milliseconds by length, so JavaScript’s 13-digit times work too.

4. Check the signature

A token that decodes isn’t necessarily genuine: anyone can write one. Under Check the signature, paste the shared secret for HS256, HS384 and HS512 tokens, or the issuer’s public key (-----BEGIN PUBLIC KEY-----) for RS, PS and ES tokens. The made-up signature above is reported as invalid.

5. Look at the certificate behind the key

Identity providers often publish their keys as certificates, in the x5c field of their JWKS document or as a .pem or .crt file. Paste or drop one into the Certificate Decoder to see who it belongs to, who issued it, when it expires and its fingerprints, which helps when a key has been rotated and tokens suddenly stop verifying.

↑ ↓ move↵ openesc close