Skip to content
AuthMantraPraxis
authmantra.com ↗Start free trial

Engineering track · 3 min

Decode a token by hand

Split a JWT, read the claims, and check what a relying party checks.

The idea

  1. 1Three parts, two dots

    A JWT is header.payload.signature, each base64url. The header names the algorithm and key id.

  2. 2The payload is claims

    iss says who issued it, sub the person, aud which app it is for, exp when it ends.

  3. 3Decoding is not verifying

    Anyone can read the payload. Only the signature, checked against the issuer's public keys in JWKS, proves it.

  4. 4Then check the claims

    Right issuer, right audience, not expired. A valid signature on the wrong audience is still a reject.

Try it

Decode, then judge

Sample tokens with harmless data. Pretend the time is 10 Oct 2026, 10:00 UTC.

This exercise needs JavaScript. Here is the answer key.

A JWT is header.payload.signature. Decode the first two with base64url and check iss, aud and exp.

Check yourself

1 of 3 What does aud tell the app?

2 of 3 Can you trust a token because you could decode it?

3 of 3 An expired token with a valid signature is

Answer key
  1. What does aud tell the app? Which app the token is meant for. Reject tokens addressed to another audience.
  2. Can you trust a token because you could decode it? No, decoding proves nothing. Verify the signature against JWKS.
  3. An expired token with a valid signature is Rejected. exp is checked as well.