Compare two JWTs
Paste two tokens to see exactly what changed — headers, claims, roles, key IDs and timestamps. Useful for refresh-token debugging, environment comparison (staging vs production) and tracking down authorization differences.
🔒 Both tokens stay in your browser.🔒 Decoded locally — never sent anywhere.0 chars
🔒 Decoded locally — never sent anywhere.0 chars
Paste two JWTs to see changed headers, claims, roles and timestamps side by side.
What to look for
- kid changed — the tokens were signed with different keys. After a key rotation, make sure verifiers have the new key in their JWKS.
- iss or aud changed — typically tokens from different environments or tenants. A token accepted in staging will be rejected by production if its issuer or audience differs.
- Roles, scopes or permissions changed — explains why one token is authorized and the other is not.
- exp/iat moved — a refreshed token should have a later exp; if not, the refresh flow may be returning a cached token.
To inspect one token in depth — signature, timeline and security checks — use the JWT decoder.