How to decode a JWT
Paste a JSON Web Token into the box — with or without the Bearer prefix copied from an Authorization header. The decoder splits it into its three parts, decodes the header and payload, and converts time claims like exp and iat into readable dates so you can see at a glance whether the token has expired.
Anatomy of a JWT
A JWT is three Base64URL-encoded segments joined by dots:
- Header — metadata, usually the signing algorithm (
alg, e.g. HS256 or RS256) and token type (typ). - Payload — the claims: who the token is about (
sub), who issued it (iss), who it's for (aud), when it expires (exp), plus any custom data such as roles or tenant IDs. - Signature — a cryptographic signature over the header and payload. It proves the token wasn't tampered with, but only a party holding the key can check it.
Registered claims reference
| Claim | Name | Meaning |
|---|---|---|
iss | Issuer | Who created and signed the token |
sub | Subject | The user or entity the token represents |
aud | Audience | Which service the token is intended for |
exp | Expiration | Unix time after which the token is invalid |
nbf | Not before | Unix time before which the token is invalid |
iat | Issued at | Unix time the token was created |
jti | JWT ID | Unique identifier, used to prevent replay |
Decoding is not verifying
Anyone can decode a JWT — the payload is just encoded, not encrypted. Your backend must always verify the signature and check exp, iss and aud before trusting a token. Common security mistakes include accepting alg: none, using weak HMAC secrets, and confusing RS256 public keys with HS256 secrets.
Debugging tips
- 401 errors right after login? Check that
expisn't in the past due to server clock drift. - Token rejected by one service only? Compare the
audclaim with what that service expects. - Missing permissions? Inspect the roles or scope claims in the payload.
Convert raw timestamps with the Unix timestamp converter, or decode individual segments with the Base64 decoder.
Frequently asked questions
Is it safe to paste my JWT here?
Decoding happens entirely in your browser — the token is never sent anywhere. Still, treat production tokens like passwords: anyone holding a valid token can use it until it expires.
Does this tool verify the JWT signature?
No. It decodes the header and payload, which are only Base64URL-encoded and readable by anyone. Verifying the signature requires the secret or public key and should be done on your server with a trusted library.
What do exp, iat and nbf mean?
They are registered claims holding Unix timestamps in seconds: exp is when the token expires, iat is when it was issued, and nbf is the time before which it must not be accepted.
Can I store sensitive data in a JWT payload?
Not in a standard signed JWT (JWS). The payload is readable by anyone who has the token. Use JWE (encrypted JWT) or keep sensitive data server-side.
Last updated: 22 September 2026Suggest an improvement · Report a problem
