Your token is decoded locally in your browser and is never sent to oauth2.dev. If you choose to save a report, only controlled, non-sensitive diagnostic labels are sent to your dashboard. Please note that this tool is intended for development and testing purposes only. Always handle cryptographic material with care and follow security best practices.
Paste any valid JWT token into the debugger to decode and visually inspect it. Valid IANA registered `claims` within the token will try to resolve to the respective specification for further reading.
Use the authorization callback catcher as the `redirect_uri` in your authentication request. Then copy the token you want to inspect from the callback catcher and paste it here.
Callback catcher redirect URI: