JWT Decoder & ValidatorSpecialized Version
🎟️

JWT Debugger

JWT Debugger

JWT Debugger

Debug and troubleshoot JWT issues by inspecting token structure, claims, and timing. This debugger helps identify why tokens might be rejected or cause authentication failures.

Key Features

  • Visual token breakdown
  • Claim inspection
  • Timestamp conversion
  • Expiration status
  • Header analysis

When to Use This Tool

Use when authentication fails unexpectedly, tokens are rejected, or you need to understand what data a token contains.

Example

Common debugging findings: • Token expired 2 hours ago (exp: 1699524800) • Wrong audience claim (expected: api.myapp.com) • Missing required claim (no "role" in payload) • Algorithm mismatch (token uses RS256, server expects HS256)

JWT Structure Explained

JSON Web Tokens consist of three Base64URL-encoded parts separated by dots:

1. Header: Contains the token type ("JWT") and signing algorithm (e.g., HS256, RS256) 2. Payload: Contains claims—statements about the user and additional metadata 3. Signature: Created by signing the header and payload with a secret key

Each part can be decoded independently, but only the signature verification confirms the token's integrity.

Standard JWT Claims Reference

ClaimNameDescription
issIssuerIdentifies who issued the token
subSubjectIdentifies the user or entity
audAudienceIntended recipient(s) of the token
expExpirationUnix timestamp when token expires
nbfNot BeforeUnix timestamp when token becomes valid
iatIssued AtUnix timestamp when token was created
jtiJWT IDUnique identifier for this token

Common JWT Algorithms

AlgorithmTypeDescriptionUse Case
HS256SymmetricHMAC with SHA-256Simple APIs with shared secret
HS384SymmetricHMAC with SHA-384Higher security symmetric signing
HS512SymmetricHMAC with SHA-512Maximum symmetric security
RS256AsymmetricRSA with SHA-256Distributed systems, public verification
RS384AsymmetricRSA with SHA-384Higher security asymmetric signing
RS512AsymmetricRSA with SHA-512Maximum asymmetric security
ES256AsymmetricECDSA with P-256Mobile apps, smaller signatures
PS256AsymmetricRSA-PSS with SHA-256Modern RSA replacement

Where JWTs Are Used

JWTs have become the standard for modern authentication and authorization:

  • Single Sign-On (SSO): Share authentication across multiple applications and services
  • API Authentication: Secure REST and GraphQL APIs with stateless token verification
  • OAuth 2.0 / OpenID Connect: Industry-standard protocols use JWTs for access and identity tokens
  • Microservices: Pass user context between services without database lookups
  • Mobile Applications: Lightweight authentication for iOS and Android apps
  • Third-Party Integrations: Securely exchange data with external services

Pro Tips

  • Compare timestamps carefully—JWT uses Unix timestamps in seconds
  • Check for extra whitespace or newlines when copying tokens
  • Verify the token was not truncated during transmission

Security Considerations

1. Signature verification: Always verify the signature on your server—never trust unverified tokens 2. Algorithm confusion: Validate the "alg" header to prevent attackers from using "none" or switching from RS256 to HS256 3. Token storage: Use httpOnly cookies when possible; localStorage is vulnerable to XSS attacks 4. Minimal payload: Include only necessary data—tokens should be small and not contain sensitive information 5. Token lifetime: Use short-lived access tokens (15-60 minutes) with refresh token rotation 6. Secret management: Keep signing keys secure; rotate them periodically; never expose them in client-side code 7. Token revocation: Plan for emergency revocation using token blacklists, version numbers, or short lifetimes

Frequently Asked Questions

Are JWTs encrypted?

Standard JWTs (JWS) are signed but not encrypted—anyone can read the payload. For encrypted tokens, use JWE (JSON Web Encryption), or simply don't put sensitive data in the token.

How should I store JWTs in a web app?

HttpOnly cookies are most secure against XSS attacks. If you must use localStorage, implement additional XSS protections. Never store tokens in sessionStorage for long-lived sessions.

What happens when a JWT expires?

The server should reject expired tokens. Implement refresh token flow: use short-lived access tokens (15-60 min) and longer-lived refresh tokens to obtain new access tokens without re-authentication.

How does jwt debugger help with authentication?

This tool helps you debug token issues. In production, always perform these operations server-side with proper secret key management.

Related Tools

Explore other tools you might find useful:

Related Calculators