Skip to content

JWT decoding vs verification: debug a token safely

Understand the difference between reading JWT claims and verifying a signature, with a practical checklist for API authentication failures.

By DevToolPlace · Published October 5, 2026 · 2 min read

What the three parts mean

A signed compact JWT commonly has a header, payload and signature separated by dots. The first two parts use Base64url encoding. Encoding is not encryption: anyone who has the token can usually read those claims. Encrypted JWTs use a different structure, so a three-part decoder is not a universal token reader.

base64url(header).base64url(payload).base64url(signature)

Read claims without treating them as evidence

Decoding a token is useful for inspecting fields, but an attacker can construct a payload claiming any user id or role. Trust comes from verifying the signature using the expected key and allowed algorithm, then validating claims for your application. Do not authorize a request merely because a decoder displays a plausible user.

Check expiry in seconds, not milliseconds

JWT NumericDate claims such as exp use seconds since the Unix epoch. JavaScript Date.now() returns milliseconds, so convert it before comparing. This diagnostic check is only one part of verification; it does not validate a signature, issuer or audience.

const nowSeconds = Math.floor(Date.now() / 1000);
const expired = typeof claims.exp === 'number'
  && nowSeconds >= claims.exp;

A useful order for investigating a 401

Confirm the token is attached to the right request and has not been truncated. Check exp and nbf against the server clock. Compare iss and aud with the API configuration. Verify that the key identifier resolves to the correct trusted key and that key rotation has propagated. Keep algorithm selection constrained by server configuration. A token valid for one API may be intentionally invalid for another.

Use a development token in online tools

A bearer token can grant access to its holder until it expires or is revoked. Use a fake or expired development token when exploring the toolkit. DevToolPlace uses server-backed operations, so do not paste production signing secrets or live tokens. Verify real tokens inside your backend with a maintained JWT library and your actual authentication policy.

Reference documentation

Try the related tools with sample data

Found an error or a missing edge case? Send a reproducible example.