What's inside this JWT?
A JSON Web Token (JWT) is the long eyJ… string that sign-in systems and APIs pass around to say who you are and
what you may do. When a request fails with 401 Unauthorized, the token is the first thing to look at. These
tools run in your browser and never put a token in a link, but treat a real token like a password all the same.
The token used here was made up for this guide:
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJhbGljZSIsImF1ZCI6ImFwaS5leGFtcGxlLmNvbSIsInNjb3BlIjoicmVhZCIsImlhdCI6MTc2NzIyNTYwMCwiZXhwIjoxNzY3MjI5MjAwfQ.c2lnbmF0dXJl
1. Make sure it’s a JWT
If you’re not sure what you’ve got, paste it into Identify first. Three Base64URL parts separated by
dots, starting eyJ, is a JWT; the header’s algorithm (here HS256) is shown too.
2. Read the claims
Paste it into the JWT Decoder. A leading Bearer is ignored, so the whole Authorization header value
works. The payload’s claims say who and what the token is for:
sub: who it was issued to (herealice).aud: which service it’s meant for (api.example.com). A token sent to a different service is usually refused.scopeorscp: what it allows (read). A write request with a read-only token fails.iat,nbfandexp: when it was issued, when it becomes valid, and when it expires.
3. Check the times
The decoder shows iat, nbf and exp in your local time with how long ago each was. This token was issued at
midnight UTC on 1 January 2026 and expired an hour later, so it says This token has expired.
For a time elsewhere (a log line, another claim such as auth_time), paste the number into the
Timestamp Converter: 1767229200 is 1 January 2026, 01:00 UTC. It tells seconds from milliseconds by
length, so JavaScript’s 13-digit times work too.
4. Check the signature
A token that decodes isn’t necessarily genuine: anyone can write one. Under Check the signature, paste the
shared secret for HS256, HS384 and HS512 tokens, or the issuer’s public key (-----BEGIN PUBLIC KEY-----) for
RS, PS and ES tokens. The made-up signature above is reported as invalid.
5. Look at the certificate behind the key
Identity providers often publish their keys as certificates, in the x5c field of their JWKS document or as a
.pem or .crt file. Paste or drop one into the Certificate Decoder to see who it belongs to, who issued
it, when it expires and its fingerprints, which helps when a key has been rotated and tokens suddenly stop
verifying.