JWT Decoder

Decode and inspect JSON Web Token headers, payloads, and claims.

Security
JWT Token
Header
Payload
⚠️ This tool decodes without verifying the signature. Never trust decoded JWT claims without server-side verification of the signature.

What is a JSON Web Token (JWT)?

A JSON Web Token (JWT, pronounced "jot") is an open standard (RFC 7519) that defines a compact, URL-safe way to represent claims between two parties. JWTs are most commonly used for authentication and information exchange in modern web applications — a server issues a JWT after login, and the client sends it with each subsequent request to prove its identity.

A JWT consists of three Base64URL-encoded parts separated by dots: the header, the payload, and the signature. The header specifies the token type and the signing algorithm (commonly HS256 or RS256). The payload contains "claims" — statements about the user and the token itself. Standard claims include sub (subject, usually the user ID), iat (issued at, Unix timestamp), exp (expiry, Unix timestamp), aud (audience), and iss (issuer). The signature is a cryptographic hash of the header and payload, signed with a secret key or private key.

The critical security point: the header and payload are Base64URL-encoded, not encrypted. Anyone with the token can read them. The signature only proves the token has not been tampered with — it does not hide the payload contents. For sensitive data, use JWE (JSON Web Encryption) which does encrypt the payload.

Common mistakes

  • Trusting decoded data without verifying the signature — Decoding a JWT is trivial. Always verify the signature on the server using the secret or public key before trusting the claims.
  • Storing JWTs in localStorage — localStorage is accessible to any JavaScript on the page, making it vulnerable to XSS attacks. HttpOnly cookies are generally more secure.
  • Not checking expiry — Always validate the exp claim on the server. An expired token with a valid signature must be rejected.