How to Test JWT Authentication
Problem: Verify tokens used by your API are formed correctly and contain expected claims.
Steps
- Obtain a token from your auth endpoint (or a sample token).
- Open JWT Decoder and paste the token.
- Check the
expclaim for expiry and expected scopes or roles. - If the payload contains encoded fragments, use Base64 Encoder to inspect them.
Checks to perform
- Token header algorithm matches expected signature algorithm.
- Claims include
sub,iat, andexpwhen required. - Expiry is in the future during tests.