Skip to content
EverythingTool logo

Developer guides

What Is a JWT? JSON Web Tokens Explained with an Example

Updated 25 September 2026 · 5 min read

A JSON Web Token (JWT, pronounced “jot”) is a compact, signed way to pass claims between systems — most often to prove who a user is after they log in. The server signs it; later requests send it back, and the server checks the signature instead of looking up a session.

A real example

This token has three parts separated by dots:

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9
.eyJzdWIiOiJ1c2VyXzQyIiwibmFtZSI6IlByaXlhIFNoYXJtYSIsInJvbGUiOiJlZGl0b3IiLCJpYXQiOjE3OTAwMDAwMDAsImV4cCI6MTc5MDAwMzYwMH0
.oS51kxrYaJINrO2op3AsACU4GZtiLJ6J0KpaPQfnfvo
  1. Header — {"alg":"HS256","typ":"JWT"}: the signing algorithm.
  2. Payload — {"sub":"user_42","name":"Priya Sharma","role":"editor","iat":1790000000,"exp":1790003600}: the claims.
  3. Signature — an HMAC-SHA256 of the first two parts using a secret only the server knows.

The header and payload are just Base64URL-encoded JSON, which is why anyone can read them.

Paste a token into the JWT decoderDecode JSON Web Tokens to inspect header, payload and expiry. Nothing leaves your browser.

Common claims

subSubject — usually the user ID
iatIssued at (Unix seconds) — 1790000000 is 21 Sep 2026, 7:43 pm IST
expExpiry — here one hour later
iss, audWho issued the token and who it's for

Timestamps are in seconds since 1970 — convert them with the Unix timestamp converter.

Signed, not encrypted

  • Anyone holding the token can read the payload, so never put passwords, card numbers or personal secrets in it.
  • Nobody can change it without the secret (HS256) or private key (RS256/ES256) — the signature would no longer match.
  • Keep expiry short, and send tokens only over HTTPS.

Next: how to decode a JWT by hand or in code.

Frequently asked questions

Is a JWT encrypted?

Usually not. A standard JWT (JWS) is only signed: anyone can decode and read the payload, but they can't change it without breaking the signature. Never put passwords or secrets in a JWT.

What are iat and exp in a JWT?

iat (issued at) and exp (expires) are Unix timestamps in seconds. The server rejects the token once the current time passes exp.

Open the JWT DecoderDecode JSON Web Tokens to inspect header, payload and expiry. Nothing leaves your browser.
Share this guide WhatsApp X Facebook

Official websites, opening in a new tab. EverythingTool isn't affiliated with them.