JWT FAQ — common JSON Web Token questions
Is it safe to paste a JWT into TokenPrism?
Yes. All decoding, verification and signing happen entirely in your browser using the Web Crypto API — the token is never sent to any server. A strict Content-Security-Policy blocks outbound requests, and the app works with your network disconnected. Even so, avoid pasting production tokens you can revoke into any online tool when you can use a redacted or test token instead.
What is a JWT?
A JSON Web Token (JWT) is a compact, URL-safe token with three base64url-encoded parts — header, payload and signature — separated by dots. It carries claims (data) and a signature that lets a receiver verify the token was issued by a trusted party and not tampered with.
Why does my JWT say "invalid signature"?
The signature is checked against the key or secret you provide. Common causes: wrong secret or public key, a secret entered as UTF-8 when it was base64url (or vice versa), an algorithm mismatch, or a token that was modified after signing. TokenPrism shows the specific reason and never reports "verified" without a matching key.
What is the difference between decoding and verifying a JWT?
Decoding just base64url-decodes the header and payload so you can read the claims — it proves nothing about authenticity. Verifying recomputes the signature with a key and confirms the token is genuine and unmodified. Anyone can decode a JWT; only someone with the key can verify it.
Is a JWT encrypted?
A standard signed JWT (JWS) is NOT encrypted — the payload is only base64url-encoded and anyone can read it. Never put secrets in a JWT payload. If you need confidentiality, use JWE (JSON Web Encryption), which TokenPrism also supports.
What is a "kid" in a JWT header?
The "kid" (key ID) header names which key signed the token, so a verifier can pick the right public key from a JWKS. Treat it as an opaque identifier: never use it to build a file path or database query, which is a known injection vector.