How to inspect a JWT safely

A JSON Web Token normally contains a header, payload, and signature. Decoding the first two is useful for debugging, but it does not prove the token is authentic.

What you can learn by decoding

The header commonly identifies the token type and signing algorithm. The payload can contain claims such as subject, issuer, audience, issued-at time and expiry.

Open JWT Inspector →

exp and iat

The exp claim usually represents the time after which the token should no longer be accepted. iat records when it was issued. These values are commonly Unix timestamps, so converting them to readable UTC and local times makes authentication problems easier to diagnose.

Decoding is not verification

Anyone can construct a JWT-shaped string. A backend must verify the signature using the expected key and algorithm before trusting claims. Never treat a browser decoder's output as proof that a token is valid.

Handle tokens as credentials

Real access tokens may grant access to accounts or APIs. Prefer redacted test tokens when possible, avoid screenshots containing full credentials, and never publish a live token in documentation or support messages.