JWT Decoder
Decode JWT tokens and inspect their header and payload.
Important
This tool only decodes the JWT header and payload. It does not verify the token signature or confirm whether the token is valid.
About JWT Decoder
Decode JSON Web Tokens in your browser and inspect the JWT header, payload and common claims without verifying the token signature.
How to use JWT Decoder
- Paste your JWT into the input box.
- Click Decode JWT.
- Review the decoded header and payload.
- Check common claims such as issuer, subject and expiration.
What is a JWT?
JWT stands for JSON Web Token. It is a compact format commonly used to transfer information between systems as a JSON object. JWTs are often used for authentication and authorization in web applications and APIs.
What are the parts of a JWT?
A typical JWT contains three parts separated by periods: Header, Payload and Signature.
| Part | Purpose |
|---|---|
| Header | Contains information about the token type and signing algorithm. |
| Payload | Contains claims and other data associated with the token. |
| Signature | Used to verify that the token has not been modified and that it was signed by the expected party. |
Common JWT Claims
| Claim | Description |
|---|---|
| iss | Identifies the issuer of the JWT. |
| sub | Identifies the subject associated with the JWT. |
| aud | Identifies the intended audience of the JWT. |
| iat | Indicates when the JWT was issued. |
| exp | Indicates when the JWT expires. |
| nbf | Indicates the time before which the JWT should not be accepted. |
Decode vs Verify a JWT
Decoding a JWT only reads the encoded header and payload. It does not prove that the information is trustworthy. Verifying a JWT requires checking its signature with the appropriate key and validation rules.
When should you use a JWT Decoder?
- Inspecting JWT headers during API development.
- Checking claims returned by an authentication system.
- Debugging token expiration and timestamp values.
- Understanding the structure of a JWT during development.