JWT Decoder

Decode JWT tokens and inspect their header and payload.

Important

This tool only decodes the JWT header and payload. It does not verify the token signature or confirm whether the token is valid.

About JWT Decoder

Decode JSON Web Tokens in your browser and inspect the JWT header, payload and common claims without verifying the token signature.

How to use JWT Decoder

  1. Paste your JWT into the input box.
  2. Click Decode JWT.
  3. Review the decoded header and payload.
  4. Check common claims such as issuer, subject and expiration.

What is a JWT?

JWT stands for JSON Web Token. It is a compact format commonly used to transfer information between systems as a JSON object. JWTs are often used for authentication and authorization in web applications and APIs.

What are the parts of a JWT?

A typical JWT contains three parts separated by periods: Header, Payload and Signature.

PartPurpose
HeaderContains information about the token type and signing algorithm.
PayloadContains claims and other data associated with the token.
SignatureUsed to verify that the token has not been modified and that it was signed by the expected party.

Common JWT Claims

ClaimDescription
issIdentifies the issuer of the JWT.
subIdentifies the subject associated with the JWT.
audIdentifies the intended audience of the JWT.
iatIndicates when the JWT was issued.
expIndicates when the JWT expires.
nbfIndicates the time before which the JWT should not be accepted.

Decode vs Verify a JWT

Decoding a JWT only reads the encoded header and payload. It does not prove that the information is trustworthy. Verifying a JWT requires checking its signature with the appropriate key and validation rules.

When should you use a JWT Decoder?

  • Inspecting JWT headers during API development.
  • Checking claims returned by an authentication system.
  • Debugging token expiration and timestamp values.
  • Understanding the structure of a JWT during development.