ToolHub

JWT Decoder

Decode JWT tokens online in your browser.

Header


        

Payload


        

Anatomy of a JSON Web Token

A JWT is three Base64URL-encoded parts joined by dots: Header.Payload.Signature

PartContains
HeaderThe token type (typ: JWT) and signing algorithm (alg: HS256).
PayloadThe claims (data) about the user and token — see standard claims below.
SignatureVerifies the token wasn't tampered with, computed over the header and payload with a secret or private key.

Standard registered claims

ClaimMeaning
subSubject — who the token is about (usually the user id)
issIssuer — who created the token
audAudience — who the token is intended for
iatIssued-at time (Unix seconds)
expExpiry time (Unix seconds) — the token is invalid after this
nbfNot-before time — the token is invalid until this

HS256 (symmetric)

One shared secret both signs and verifies the token. Simple, but every party that can verify can also forge — keep the secret private.

RS256 (asymmetric)

A private key signs and a public key verifies. Others can verify tokens without being able to issue them — better for distributed systems.

About JWT Decoder

Decode a JSON Web Token (JWT) to inspect its header and payload in readable JSON. See the claims, algorithm, and expiry — decoded entirely in your browser so tokens stay private.

How to Use

  1. Paste your JWT (the xxxxx.yyyyy.zzzzz string).
  2. The header and payload are Base64URL-decoded and shown as JSON.
  3. Inspect the claims, algorithm, and expiry.
  4. Nothing is sent anywhere — safe for real tokens.

Why Use This Tool?

Frequently Asked Questions

Does decoding a JWT verify its signature?

No. Decoding only reads the header and payload, which are Base64-encoded, not encrypted. Verifying authenticity requires the secret or public key and is done server-side — never trust a decoded JWT without verifying it.

Is it safe to paste a real token here?

The decoding happens entirely in your browser and the token is never transmitted. That said, treat live tokens carefully and avoid pasting them into tools you don't trust.

Why can I read the payload without a key?

A JWT's header and payload are only Base64URL-encoded, not encrypted, so anyone can read them. The signature merely proves the token wasn't altered — it does not hide the contents.

Related tools