JWT Decoder

Decode and inspect JSON Web Tokens instantly. View header, payload, claims, and expiry status. All processing happens in your browser.

Paste a JWT token above and click "Decode" to inspect its contents.
Advertisement

About JWT Decoder

A JSON Web Token (JWT) is a compact, URL-safe token format used to securely transmit information between parties as a JSON object. JWTs are widely adopted in modern web applications for authentication, authorization, and information exchange. They are self-contained, meaning the token itself carries all the information needed to verify the identity and permissions of a user, eliminating the need for server-side session storage.

Every JWT consists of three parts separated by dots: a header, a payload, and a signature. The header typically specifies the signing algorithm (such as HMAC SHA-256 or RSA) and the token type. The payload contains the claims, which are statements about an entity (usually the user) and additional metadata. The signature is created by combining the encoded header, encoded payload, and a secret key to ensure the token has not been tampered with.

How JWTs Work

When a user logs in, the server generates a JWT and sends it back to the client. The client stores this token (usually in local storage or an HTTP-only cookie) and includes it in subsequent requests via the Authorization header. The server validates the signature on each request to confirm the token is authentic and has not been modified. This stateless approach eliminates the need for session databases and scales well across distributed systems.

Common Use Cases

Authentication: After login, every subsequent request includes the JWT, allowing the server to verify the user without querying a database. Single Sign-On (SSO): JWTs enable users to authenticate once and access multiple services that trust the same token issuer. API Authorization: Microservices use JWTs to verify that requests originate from authenticated and authorized clients. Information Exchange: Because JWTs can be signed, the receiver can verify the sender's identity and ensure the content has not been altered in transit.

This tool decodes JWTs entirely in your browser. No token data is ever sent to a server, making it safe to inspect tokens containing sensitive information. Simply paste your token, and the decoder will display the header, payload, registered claims, signature, and expiration status.

FAQ

Q: What is a JWT token?
A JSON Web Token is a compact string composed of three Base64URL-encoded parts (header, payload, and signature) separated by dots. It is defined by RFC 7519 and is the standard mechanism for transmitting authenticated claims between a client and a server in modern web and mobile applications.

Q: Is it safe to decode JWTs online?
Yes, when using a client-side tool like this one. All decoding happens entirely in your browser using JavaScript. No data is transmitted to any server. You can verify this by checking the network tab in your browser's developer tools. However, you should never paste JWTs into server-side tools from untrusted sources, as the token payload may contain sensitive information.

Q: Can you modify a JWT token?
You can decode and read the header and payload of any JWT without the signing key, because they are simply Base64URL-encoded JSON. However, if you modify any part of the token, the signature will no longer match, and any properly implemented server will reject the tampered token. The security of a JWT depends on the integrity of its signature.

Q: What are common JWT claims?
The JWT specification defines several registered claims: iss (issuer), sub (subject), aud (audience), exp (expiration time), nbf (not before), iat (issued at), and jti (JWT ID). Applications can also define custom claims to carry additional data such as user roles, permissions, or profile information.

Q: How do JWT tokens expire?
A JWT can include an exp (expiration) claim, which is a Unix timestamp indicating when the token becomes invalid. When a server receives a JWT, it checks the current time against the exp value. If the token has expired, the server rejects the request. Short-lived tokens (typically 15 minutes to 1 hour) combined with refresh tokens provide a balance between security and user convenience.

Advertisement