A worked example, rendered from real sample data. Sign in to run the tool on your own input.
eyJhbGciOiJFUzI1NiIsInR5cCI6ImF0K2p3dCIsImtpZCI6ImlkcC0yMDI2LTA5In0.eyJpc3MiOiJodHRwczovL2lkcC5hY21lLmV4YW1wbGUiLCJzdWIiOiJ1c3JfOGYzMWMwYTIiLCJhdWQiOiJodHRwczovL2FwaS5hY21lLmV4YW1wbGUiLCJjbGllbnRfaWQiOiJ3ZWItZGFzaGJvYXJkIiwiZXhwIjoxODIwMDAwMDAwLCJpYXQiOjE3ODkwMDAwMDAsImp0aSI6ImFjY180ZjJiMWQ3ZTkwIiwic2NvcGUiOiJvcGVuaWQgcHJvZmlsZSBlbWFpbCBvZmZsaW5lX2FjY2VzcyByZWFkOm9yZGVycyB3cml0ZTpvcmRlcnMifQ.44fykUusOu4RPWYWBm74xdMEFunYjfnwDSVO2rVVWyhcubiEYt9i5fDTzDDrpzWPZ2kqM77_dsiJW6TI92dOaw═══ token 1 — Access token (RFC 9068 JWT profile) ═══
Algorithm: ES256
Key id: idp-2026-09
Header typ: at+jwt
Segments: 67c · 326c · 86c
Size: 481 bytes
─── Registered claims ───
iss: https://idp.acme.example
• Issuer — the authorization server that minted this token. Pin it exactly; never trust a token from an unexpected issuer.
sub: usr_8f31c0a2
• Subject — the stable, opaque id of the end user or service the token is about.
aud: https://api.acme.example
• Audience — the API that is allowed to accept this token. Your resource server must reject anything else.
exp: 2027-09-03T19:33:20Z (in 348 days)
• Expires at — a verifier must refuse the token after this instant.
iat: 2026-09-10T00:26:40Z (10 days ago)
• Issued at — when the authorization server created the token.
jti: acc_4f2b1d7e90
• JWT id — a unique id used for replay detection and revocation lists.
─── Scopes (6) ───
openid: Turns an OAuth request into an OpenID Connect one. Without it you get no ID token.
profile: Basic profile claims: name, family_name, given_name, picture, locale, updated_at.
email: The email and email_verified claims.
offline_access: Asks for a refresh token so the client can keep working when the user is away.
read:orders: Read-only access to orders.
write:orders: Create and modify orders. Implies read on most issuers, but do not assume it.
ℹ offline_access was granted, so a refresh token exists. Revoking the access token alone does not end this session.
─── Issuer-specific claims (1) ───
client_id: web-dashboard
─── Verdict ───
✓ Valid for another 348 days.
⚠ Lifetime of 359 days is long
…
Decode OAuth 2 and OIDC tokens, explain every claim and scope, and name opaque ones. Part of the DevTools Surf developer suite. Browse more tools in the Security / Crypto collection.