Debugging a 401 that looks correct
A token that decodes cleanly but returns 401 usually fails on aud or iss rather than expiry. Compare the aud claim against the API's expected audience before assuming a clock problem.
Decode a JSON Web Token and inspect claims and expiry in your browser.
Maintained by Roshan.
Decoding is not signature verification. Treat a bearer token like a password.
Find related browser-local tools for nearby tasks without starting another search.
Browse all developer and data toolsA JSON Web Token is three base64url segments joined by dots: a header describing the signing algorithm, a payload of claims, and a signature. Decoding reveals the first two instantly. The important thing to understand - and the thing most decoders bury - is that decoding is not verification. A token whose contents look correct can still be forged. This decoder makes that distinction explicit, and because a bearer token is a live credential, it does the work in your browser rather than sending it to anyone.
A token that decodes cleanly but returns 401 usually fails on aud or iss rather than expiry. Compare the aud claim against the API's expected audience before assuming a clock problem.
If nbf is a few seconds in the future relative to the verifying server, the token is rejected as not yet valid. Most libraries allow a small leeway setting for exactly this.
This page decodes in your browser without sending the token in a request; verify that in the Network panel. Treat every bearer token as a live password, and rotate one if it was exposed to an untrusted service.
Validity requires the signing key. For HS256 that is a shared secret and for RS256 it is the issuer's public key, fetched from a JWKS endpoint. Verifying in the browser would mean asking you to paste a secret into a web page, which is worse practice than the problem it solves.
It declares an unsigned token. It exists in the specification for cases where integrity is guaranteed by another layer, but it is overwhelmingly seen as an attack: strip the signature, set alg to none, and hope the server trusts the header. Any verifier that accepts it is broken.
The timestamp was read as milliseconds when JWT uses seconds. Multiply by 1000 before constructing a Date. This decoder handles the conversion for you in the formatted claim display.
Format, minify, and validate JSON locally in your browser. Inspect keys, values, nesting depth, and root type without sending private API data to a server.
Convert JSON objects to UTF-8 CSV in your browser. Union columns, quote values, and protect formula-like strings.
Percent-encode and decode URLs in your browser, choosing between encoding a value inside a URL and encoding a whole address. Shows which characters differ.
Decode a QR code from a photo or screenshot and read its destination as text before following it. Runs in your browser.
Turn a JSON array into JSON Lines in your browser, one record per line, ready for streaming tools.