A JSON Web Token looks unreadable at first because it is split into base64url sections. A JWT decoder turns the header and payload back into readable JSON so you can inspect claims such as issuer, subject, audience, issued-at time, and expiration time.
Decode means read, not trust
The most important distinction is simple: decoding a JWT is not the same as verifying it. Anyone can decode a JWT payload because the data is encoded, not encrypted. Verification requires the correct secret or public key and confirms that the token signature matches.
This matters because a forged token can still decode into convincing-looking JSON. Your application should never trust a token just because the fields look correct in a decoder. Decoding is a debugging step; verification is a security step.
Think of a decoder as a way to inspect the envelope and message. It can show what the token claims, but it cannot prove who wrote it unless the signature is checked by the correct authentication code.
What to inspect in a JWT
Start with the header. Check the algorithm and token type. Then read the payload claims. Common fields include iss for issuer, sub for subject, aud for audience, iat for issued-at time, nbf for not-before time, and exp for expiration time.
If an API request is failing, compare the audience, issuer, and expiration with the service configuration. Many token bugs are caused by a token intended for one API being sent to another. Time claims can also confuse debugging because JWT timestamps are commonly Unix timestamps in seconds, while logs may show local time or UTC.
Custom claims deserve the same attention. Applications often add roles, tenant IDs, permission scopes, plan names, or feature flags. If one of those values is missing or named differently than the API expects, the request can fail even when the token itself is valid.
Safe debugging workflow
- Use a sample or test token when possible.
- Decode the token and check claims.
- Compare issuer, audience, and expiration against the receiving service.
- Remove private values before sharing screenshots.
- Verify the signature in your auth library, not in a casual decoder.
For decoded payloads, use the JSON Viewer or JSON Formatter when you need to inspect nested data more comfortably.
What not to paste into public examples
A live bearer token can grant access until it expires, and some systems issue long-lived tokens. Avoid sharing production tokens, customer account IDs, internal hostnames, email addresses, or permission scopes that reveal private system structure. If you need help in a public forum, create a fake token with the same claim names but harmless values.