A JSON Web Token is three Base64url segments separated by dots: a header describing the signing algorithm, a payload of claims, and a signature. The first two are merely encoded, not encrypted, so anyone holding a token can read everything in it.
How to use the JWT Decoder
- Paste the full JWT, including both dots
- Read the decoded header to see the signing algorithm
- Read the payload claims
- Check exp against the current time to see whether the token is still valid
A JWT payload is public
This is the single most important thing to understand about JWTs. The payload is Base64url-encoded, which is reversible by anyone — including this page, with no key involved.
The signature guarantees the token has not been modified. It does nothing to keep the contents secret. Never put anything confidential in a JWT payload: no passwords, no personal data beyond what the client is allowed to see, no internal system details.
Treat a token's contents as though they were printed on the outside of the envelope, because effectively they are.
The standard claims
ississuer — who created the token.subsubject — who it is about, usually a user ID.audaudience — who it is intended for.expexpiry — Unix timestamp after which it must be rejected.iatissued at — when it was created.nbfnot before — when it becomes valid.
Timestamps are Unix seconds, not milliseconds. Use the Unix Timestamp Converter to read them. Note that decoding shows whether a token has expired, but only the server can confirm the signature is genuine — a decoder cannot validate a token without the signing key.
Frequently asked questions
Is it safe to paste a JWT here?
Decoding happens entirely in your browser and nothing is transmitted. That said, a live token is a credential — treat it with the same care as a password and prefer expired or test tokens where possible.
Can this verify the signature?
No. Verification requires the secret or public key, which only the issuing server holds. Decoding shows you the contents; it does not prove the token is authentic.
Is the payload encrypted?
No — only Base64url encoded, which anyone can reverse. Never store confidential data in a JWT payload.
What does alg: none mean?
An unsigned token. It was a serious vulnerability in several early libraries, which accepted alg: none and skipped verification entirely. Any correct implementation rejects it.