Developer guides
What Is a JWT? JSON Web Tokens Explained with an Example
Updated 25 September 2026 · 5 min read
A JSON Web Token (JWT, pronounced “jot”) is a compact, signed way to pass claims between systems — most often to prove who a user is after they log in. The server signs it; later requests send it back, and the server checks the signature instead of looking up a session.
A real example
This token has three parts separated by dots:
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9
.eyJzdWIiOiJ1c2VyXzQyIiwibmFtZSI6IlByaXlhIFNoYXJtYSIsInJvbGUiOiJlZGl0b3IiLCJpYXQiOjE3OTAwMDAwMDAsImV4cCI6MTc5MDAwMzYwMH0
.oS51kxrYaJINrO2op3AsACU4GZtiLJ6J0KpaPQfnfvo- Header —
{"alg":"HS256","typ":"JWT"}: the signing algorithm. - Payload —
{"sub":"user_42","name":"Priya Sharma","role":"editor","iat":1790000000,"exp":1790003600}: the claims. - Signature — an HMAC-SHA256 of the first two parts using a secret only the server knows.
The header and payload are just Base64URL-encoded JSON, which is why anyone can read them.
Paste a token into the JWT decoderDecode JSON Web Tokens to inspect header, payload and expiry. Nothing leaves your browser.Common claims
sub | Subject — usually the user ID |
iat | Issued at (Unix seconds) — 1790000000 is 21 Sep 2026, 7:43 pm IST |
exp | Expiry — here one hour later |
iss, aud | Who issued the token and who it's for |
Timestamps are in seconds since 1970 — convert them with the Unix timestamp converter.
Signed, not encrypted
- Anyone holding the token can read the payload, so never put passwords, card numbers or personal secrets in it.
- Nobody can change it without the secret (HS256) or private key (RS256/ES256) — the signature would no longer match.
- Keep expiry short, and send tokens only over HTTPS.
Next: how to decode a JWT by hand or in code.
Frequently asked questions
Is a JWT encrypted?
Usually not. A standard JWT (JWS) is only signed: anyone can decode and read the payload, but they can't change it without breaking the signature. Never put passwords or secrets in a JWT.
What are iat and exp in a JWT?
iat (issued at) and exp (expires) are Unix timestamps in seconds. The server rejects the token once the current time passes exp.
