Start with the header algorithm
Check whether the alg value matches the algorithm your environment is supposed to use. A mismatch is a common source of failed verification.
브라우저 내부 처리
Decode JWTs, inspect claims, review expiry, and verify signatures with JWKS.
Check whether the alg value matches the algorithm your environment is supposed to use. A mismatch is a common source of failed verification.
exp, nbf, and iat should be interpreted alongside server clock differences. Time drift often looks like a token issue at first.
JWTs are only encoded, not encrypted. If the payload contains sensitive personal or secret values, the token design itself may need review.
Being able to decode a token only means you can inspect it. Trusting it still requires signature validation.
In OIDC and external identity-provider setups, JWKS verification helps confirm that the token actually came from the issuer you expect.
JWT debugging often pairs well with JSON Formatter, the Base64 converter, and API Request Tester when you need to reproduce the full request flow.
The header and payload are Base64URL encoded, not encrypted, so anyone can read them. Reading the payload without checking the signature means trusting a token whose role an attacker changed to admin. A library's decode() does not verify.
Attacks include switching alg to none and stripping the signature, or switching RS256 to HS256 so the public key is used as an HMAC secret. Pin the allowed algorithm in code — a token header is input, not configuration.
Since anyone can decode it, a token carrying national ID numbers, internal identifiers or detailed permissions is a disclosure by itself. A token in a server log is a usable credential until it expires.
Start by comparing alg, typ, iss, aud, sub, and exp against the environment you expect. That narrows the problem quickly.
Translate exp, nbf, and iat into human-readable time and account for server clock skew. The timestamp converter pairs well with this step.
A readable token is not automatically a trustworthy one. When an external issuer is involved, use the JWKS URL to verify the signature explicitly.