Engineering track · 3 min
Decode a token by hand
Split a JWT, read the claims, and check what a relying party checks.
The idea
1Three parts, two dots
A JWT is header.payload.signature, each base64url. The header names the algorithm and key id.
2The payload is claims
iss says who issued it, sub the person, aud which app it is for, exp when it ends.
3Decoding is not verifying
Anyone can read the payload. Only the signature, checked against the issuer's public keys in JWKS, proves it.
4Then check the claims
Right issuer, right audience, not expired. A valid signature on the wrong audience is still a reject.
Try it
Decode, then judge
Sample tokens with harmless data. Pretend the time is 10 Oct 2026, 10:00 UTC.
This exercise needs JavaScript. Here is the answer key.
A JWT is header.payload.signature. Decode the first two with base64url and check iss, aud and exp.
Check yourself
1 of 3 What does aud tell the app?
2 of 3 Can you trust a token because you could decode it?
3 of 3 An expired token with a valid signature is
Answer key
- What does aud tell the app? Which app the token is meant for. Reject tokens addressed to another audience.
- Can you trust a token because you could decode it? No, decoding proves nothing. Verify the signature against JWKS.
- An expired token with a valid signature is Rejected. exp is checked as well.
Go deeper
Field notes
Blueprints
Unified sign-inBlueprintLexicon