How to Safely Decode and Inspect JSON Web Tokens (JWT) Locally
JSON Web Tokens (JWT) are the standard mechanism for representing authenticated claims between a client and server in modern web and mobile applications (OAuth 2.0, OpenID Connect).
When debugging authentication bugs, inspecting token scopes, or checking expiration times, developers frequently paste tokens into online debuggers. However, pasting production JWTs into third-party web tools can inadvertently leak active session credentials, user emails, and internal authorization scopes to external servers.
The Anatomy of a JWT
A standard JWT consists of three parts separated by periods (.):
$$\text{Header} . \text{Payload} . \text{Signature}$$
1. Header
The header contains metadata regarding the token type and cryptographic signing algorithm (such as RS256 or HS256):
{
"alg": "HS256",
"typ": "JWT"
}
2. Payload (Claims)
The payload contains statement claims about the user or session. Common standard claims include:
iss(Issuer): Who issued the token.sub(Subject): The unique user ID.aud(Audience): Who the token is intended for.exp(Expiration Time): Unix epoch timestamp when the token becomes invalid.iat(Issued At): Unix timestamp of generation.nbf(Not Before): Token cannot be accepted before this time.
{
"sub": "user_12345",
"name": "Alex Morgan",
"role": "admin",
"exp": 1790899200
}
3. Signature
The cryptographic hash ensuring that the header and payload were not tampered with in transit.
How to Safely Inspect Tokens
Because the header and payload are simply Base64URL-encoded JSON (not encrypted), anyone holding the token can decode and view its contents without knowing the secret verification key.
However, pasting live production bearer tokens into random websites is a severe security vulnerability.
Decode JWTs 100% Client-Side with UtilsConsole
The UtilsConsole JWT Decoder & Inspector provides complete security:
- Zero Server Uploads: Decoding executes strictly in your browser using local JavaScript Base64URL parsing. Tokens never touch any network socket.
- Human-Readable Timestamps: Automatically parses
exp,iat, andnbfUnix timestamps into local calendar dates and times. - Expiration Status: Visual indicator shows whether the token is currently active or expired.
- JSON Formatting: Formats and highlights header and payload JSON with 1-click clipboard copy.
Inspect your tokens safely now with the UtilsConsole JWT Decoder.