JWT Decoder for Keycloak

Your data never leaves your browser

Keycloak tokens have rich RBAC data. Decode to debug role-based access.

Example

[Paste your Keycloak token here]

Tips

  1. 1realm_access.roles: global. resource_access: per-client.
  2. 2Check azp for client used.
  3. 3Large tokens from many roles.

Frequently Asked Questions

Realm vs client roles?

Realm: global. Client: per-app.

Token too large?

Configure role scope mappings.

Offline tokens?

JWTs with typ 'Offline'.