JSON Web Token Decoder

Paste a JWT below to instantly decode the header, payload, and inspect all claims. 100% client-side — your token never leaves your browser.

Encoded Token
Paste a JWT token above to decode it

What is a JSON Web Token (JWT)?

A JSON Web Token is a compact, URL-safe means of representing claims to be transferred between two parties. It is defined in RFC 7519 and widely used for authentication and authorisation in web applications and APIs.

Structure

A JWT consists of three Base64URL-encoded parts separated by dots (.):

  • Header — Declares the token type (typ) and signing algorithm (alg), e.g. HS256, RS256.
  • Payload — Contains the claims: statements about the subject and additional metadata. Can include standard registered claims as well as custom private claims.
  • Signature — Used to verify that the token has not been tampered with. Produced by signing the encoded header + payload with a secret or private key.

Standard Registered Claims

  • iss — Issuer. Who issued the token.
  • sub — Subject. Who the token is about.
  • aud — Audience. Who the token is intended for.
  • exp — Expiration time. Unix timestamp after which the token is invalid.
  • nbf — Not Before. Unix timestamp before which the token is not valid.
  • iat — Issued At. Unix timestamp when the token was issued.
  • jti — JWT ID. A unique identifier for the token.

Security Note

This tool only decodes the JWT — it does not verify the signature. A decoded token shows you its contents, but you should always verify the signature on your server using the appropriate secret or public key before trusting any claims in a security-sensitive context.