Debug JWT & API Auth
Debug your API authentication: decode JWT tokens, check timestamps and validity, and decode Base64 fragments. All runs in your browser.
Your progress is stored only in your own browser (localStorage) and is not transmitted to our servers. Third-party resources (e.g. advertising and analytics from Google/Cloudflare) may transfer data when loaded.
This workflow guides you through the following steps:
- 1. Decode the token Decode the JWT with the JWT Decoder and read payload and expiry.
- 2. Check timestamps Check the token's iat and exp in the Timestamp Converter.
- 3. Decode Base64 Decode Base64 passages from the payload if present.
- 4. Format JSON Format messy JSON for better readability.
- 5. Encode URL Encode URL parameters correctly for requests.
Interactive workflow loading …
What you get at the end
A decoded JWT, checked timestamps, and readable Base64 or JSON fragments to keep testing.
Why these steps in this order
Token first, then timestamps, then the encoded parts. Work through the auth layer error by error.
More background
Understand formats: JSON, Base64 and more
Frequently asked questions
Where is my data stored?
Your playbook progress is saved in your own browser using localStorage. Nothing you enter is uploaded to our servers. Clearing your browser data resets the workflow.