OAuth & JWT Debugger

Decode JWTs, build OAuth 2.0 authorization URLs, and inspect access tokens. Entirely client-side — your tokens never leave your browser.

ValidRS2563 scopes
Header
algRS256
typJWT
kidabc123
Payload
subuser_12345
isshttps://auth.example.com
audhttps://api.example.com
exp
9999999999
Sat, 20 Nov 2286 17:46:39 GMT
95043d 23h from now
iat
1700000000
Tue, 14 Nov 2023 22:13:20 GMT
1020d 19h ago
nbf
1700000000
Tue, 14 Nov 2023 22:13:20 GMT
1020d 19h ago
scope
read:profilewrite:postsdelete:own
emailjohn@example.com
roles[ "admin", "user" ]
Scopes
read:profilewrite:postsdelete:own
Signature (raw base64url)
SIGNATURE_NOT_VERIFIED
Signature verification requires your secret/public key — not performed client-side.