JSON Web Token Decoder
Paste a JWT below to instantly decode the header, payload, and inspect all claims. 100% client-side — your token never leaves your browser.
Encoded Token
Paste a JWT token above to decode it
What is a JSON Web Token (JWT)?
A JSON Web Token is a compact, URL-safe means of representing claims to be transferred between two parties. It is defined in RFC 7519 and widely used for authentication and authorisation in web applications and APIs.
Structure
A JWT consists of three Base64URL-encoded parts separated by dots (.):
- Header — Declares the token type (
typ) and signing algorithm (alg), e.g.HS256,RS256. - Payload — Contains the claims: statements about the subject and additional metadata. Can include standard registered claims as well as custom private claims.
- Signature — Used to verify that the token has not been tampered with. Produced by signing the encoded header + payload with a secret or private key.
Standard Registered Claims
iss— Issuer. Who issued the token.sub— Subject. Who the token is about.aud— Audience. Who the token is intended for.exp— Expiration time. Unix timestamp after which the token is invalid.nbf— Not Before. Unix timestamp before which the token is not valid.iat— Issued At. Unix timestamp when the token was issued.jti— JWT ID. A unique identifier for the token.
Security Note
This tool only decodes the JWT — it does not verify the signature. A decoded token shows you its contents, but you should always verify the signature on your server using the appropriate secret or public key before trusting any claims in a security-sensitive context.