A leading Bearer, surrounding quotes and any line breaks are stripped for you, so paste the header line straight out of your terminal.
The shared secret the issuer signs with. It stays in your browser; nothing is sent anywhere.
{
"alg": "HS256",
"typ": "JWT",
"kid": "2026-06-key"
}{
"iss": "https://auth.example.com",
"sub": "user_8f14e45f",
"aud": "api.example.com",
"name": "John Doe",
"admin": true,
"iat": 1770000000,
"nbf": 1770000000,
"exp": 2100000000,
"jti": "9c1a0c7e-4b2d"
}Issuer. Who minted and signed the token.
Subject. Who or what the token is about, usually a user id.
Audience. Who the token is for; a receiver missing from this list should refuse it.
Full name of the user, from OpenID Connect.
Set by whoever issues the token; not part of any spec.
Issued at. When the token was minted.
Not before. The token must be refused until this moment.
Expires at. The token must be refused at or after this moment.
JWT id. Unique per token, so a replayed one can be spotted.
Times are shown in UTC, because that is what a NumericDate means. Anything the specs do not define is marked as the issuer's own.