It is 2am, logins are failing in staging, and the entire difference between shipping the fix and staring at the ceiling is one question: what is actually inside this token? I have been there more times than I will admit, squinting at eyJhbGciOi... like it might confess. JWTs look opaque but are barely encoded at all — two base64url JSON blobs you can read in seconds once you know the trick. This guide teaches the trick, and the free tool does it for you.
Anatomy of Three Dots
Every JWT is header.payload.signature — three base64url segments joined by dots. The header names the algorithm (HS256, RS256) and type. The payload carries claims: standard ones like iss (who issued it), sub (whose token), aud (who it is for), and the time trio iat/nbf/exp — plus whatever custom fields your auth server stuffed in. The signature proves nobody tampered with the first two, verifiable only with the secret or public key. Paste all three parts into our JWT Decoder and each layer unpacks into readable tables, with exp translated to a real date plus a live EXPIRED-or-valid badge.
The 2am Debugging Playbook
- Decode first, theorize later. Half of all "auth is broken" incidents are expired test tokens or tokens minted for the wrong audience — both visible in five seconds flat.
- Read exp against your clock. Short-lived staging tokens (looking at you, 5-minute lifetimes) die mid-debug-session. If
expis in the past, mint fresh before touching code. - Check aud and iss. Tokens for the wrong environment or service fail with maddeningly generic 401s. The claims table spells out exactly who the token thinks it belongs to.
- Verify signature server-side. A decodable token is not a valid token — only your backend, holding the secret, can confirm integrity.
JWT FAQs
Can anyone read my JWT?
Anyone holding it, yes — payloads are encoded, not encrypted. Never put passwords, personal data, or anything sensitive in claims. If it must stay secret, it does not belong in a token.
Why does login fail with a valid-looking token?
Usual suspects in order: expired exp, wrong aud, clock skew between servers, revoked refresh chain, or a signature mismatch from key rotation. The decoder eliminates the first three in under a minute.
What is the difference between JWT and sessions?
Sessions store state on the server and hand the client an opaque ID; JWTs hand the client the state itself, signed. JWTs scale statelessly across services but cannot be individually revoked before expiry — the fundamental tradeoff driving the whole debate.
Staring at an eyJ blob right now? Decode it.
Decode JWT Free