JWT Decoder
Decode any JSON Web Token instantly. Your token is processed entirely in the browser — it never touches a server.
// Paste a JWT above// Paste a JWT above—
// Paste a JWT above
Understanding JSON Web Tokens (JWT)
JWT Structure (RFC 7519)
JSON Web Tokens (JWT), defined in RFC 7519, are a compact, URL-safe means of representing claims transferred between two parties. A JWT consists of three Base64URL-encoded parts separated by dots (.): the Header, Payload, and Signature.
Standard JWT Claims (RFC 7519 §4.1)
| Claim | Full Name | Description |
|---|---|---|
| iss | Issuer | Identifies the principal that issued the JWT |
| sub | Subject | Identifies the principal that is the subject of the JWT |
| aud | Audience | Identifies the recipients the JWT is intended for |
| exp | Expiration Time | Unix timestamp after which the JWT must not be accepted |
| nbf | Not Before | Unix timestamp before which JWT must not be accepted |
| iat | Issued At | Unix timestamp when the JWT was issued |
| jti | JWT ID | Unique identifier for the JWT (prevents replay attacks) |
Common JWT Signing Algorithms
HS256— HMAC-SHA256 (symmetric, shared secret)RS256— RSA-SHA256 (asymmetric, public/private key pair)ES256— ECDSA-SHA256 (elliptic curve, compact signatures)PS256— RSASSA-PSS-SHA256 (RSA with probabilistic signature scheme)
⚠️ Security Warning
JWTs are Base64URL-encoded, not encrypted. Sensitive data in the payload is readable by anyone who has the token. Use JWE (JSON Web Encryption, RFC 7516) if payload confidentiality is required.
Frequently Asked Questions
Can this tool verify if a JWT signature is valid?
This decoder reads and displays the header and payload of any JWT without needing the secret key, since those parts are only Base64URL-encoded, not encrypted. Full cryptographic signature verification requires the issuer's secret or public key, which this client-side tool does not have access to.
Is it safe to paste a production JWT into this tool?
Decoding happens entirely in your browser and the token is never transmitted anywhere, but as a general security practice you should avoid pasting live, unexpired tokens into any online tool, since anyone who obtains a valid JWT can potentially use it until it expires.
What's inside a JWT's payload?
The payload contains "claims" — statements about the user or token, such as the subject (sub), expiration time (exp), issued-at time (iat), and any custom application-specific data the issuer chose to include.
Why does my JWT have three parts separated by dots?
A JWT consists of a header (algorithm and token type), a payload (claims), and a signature — each Base64URL-encoded and joined with periods, in the format header.payload.signature.
⚡ Related Developer Tools
View All 30+ Tools →Hash Generator
SHA-256, SHA-512, and SHA-1 cryptographic hashing using browser SubtleCrypto API.
Password Generator
Cryptographic high-entropy passwords, API tokens, and secure passphrases.
Password Strength Checker
Test password security privately. Calculates entropy bits, estimated crack time, and weakness flags.