JWT Decoder
Decode and inspect JWT tokens — view header, payload, and signature information instantly.
What Is JWT?
JWT (JSON Web Token) is an open standard (RFC 7519) for securely transmitting information between parties as a JSON object. A JWT is digitally signed, meaning it can be verified and trusted. Our free JWT decoder online lets you inspect the contents of any JWT token without sending it to a server.
Structure of a JWT
A JWT consists of three parts separated by dots:
header.payload.signature
Header
Contains the token type and signing algorithm (e.g., HS256, RS256).
Payload
Contains the claims — statements about an entity and additional data. Standard claims include sub, iat, exp.
Signature
Verifies the token hasn't been tampered with. Created by signing the encoded header and payload with a secret key.
What Is Base64Url Encoding?
JWT uses Base64Url encoding, which is a URL-safe variant of Base64.
Unlike standard Base64, it uses - instead of
+ and _ instead of
/, and omits padding =
characters. This JWT payload decoder automatically handles this encoding
when decoding tokens.
Common JWT Use Cases
- Authentication — Users receive a JWT after logging in, which they send with each request to verify their identity.
- API Authorization — Backend services use JWTs to authorize access to protected API endpoints.
- SaaS Sessions — SaaS platforms use JWTs to maintain session state across distributed microservices.
- Single Sign-On — SSO protocols like OpenID Connect use JWTs to transmit identity information.
- Password Reset — Time-limited JWTs encode password reset tokens with expiration claims.
Is JWT Secure?
JWT tokens are signed, not encrypted. The header and payload are Base64Url-encoded, not encrypted — anyone with the token can decode and read them. Never put sensitive data in a JWT payload. The signature ensures the token hasn't been modified, but it does not protect the contents from being viewed. Our JWT token decoder shows exactly what data is visible in any JWT.
JWT Token Example
Encoded JWT
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
Decoded Header
{"alg":"HS256","typ":"JWT"} Decoded Payload
{"sub":"1234567890","name":"John Doe","iat":1516239022} JSON Web Tokens (JWT), defined in RFC 7519, are compact, URL-safe security tokens widely used for authentication and authorization in modern web applications, microservices, and OAuth 2.0 / OpenID Connect flows. A JWT consists of three Base64URL-encoded strings separated by dots: the Header (identifying the token type and cryptographic signing algorithm such as HS256 or RS256), the Payload (containing claims like user ID, roles, issuer, and expiration time), and the Signature (used to verify token authenticity and integrity). Decoding a JWT is the first step in diagnosing authentication failures, expired sessions, and authorization permission issues. A common misconception among developers is that JWT payloads are encrypted: in standard JWS (JSON Web Signature), the payload is simply encoded in Base64URL, meaning anyone who inspects the token can read the claims. WebUtil's JWT Decoder & Token Inspector decodes the header and payload into formatted JSON, calculates token expiration status, and highlights standard claims instantly. All decoding executes 100% client-side in your browser: sensitive access tokens, refresh tokens, and internal user claims are never transmitted to any external server.
How to Do This in Code
Deploy Your Next Project Fast
Get $200 free credit on DigitalOcean to deploy your apps with blazing-fast infrastructure.
Related Tools
Related Guides & Tutorials
Understanding Online Tool Security: Why Client-Side Matters
Discover the security implications of using online developer tools and why client-side processing is crucial for data privacy.
Common JWT Errors and How to Debug Them
A practical guide to debugging JWT parsing errors — base64 decoding issues, Bearer prefix problems, signature mismatches, and how to fix them.
JWT Decoder FAQ
Can a JWT be decoded without knowing the secret signature key?
Yes. Standard JWTs (JWS) are signed, not encrypted. The header and payload are Base64URL-encoded JSON strings that anyone can decode and read without the signing secret.
What is the difference between a JWT header, payload, and signature?
The Header specifies metadata and the signing algorithm (e.g. RS256). The Payload contains the claims and data (user ID, expiration, roles). The Signature cryptographically verifies that the token was not modified after issuance.
What are standard JWT registered claims (iss, sub, aud, exp, iat)?
Standard claims include: iss (issuer), sub (subject/user ID), aud (audience/intended recipient), exp (expiration timestamp), nbf (not before timestamp), and iat (issued-at timestamp).
What is the 'alg: none' JWT vulnerability?
It is a severe security vulnerability where flawed authentication libraries accept tokens that specify 'none' as their algorithm, bypassing signature verification entirely.
Is it safe to paste production authentication tokens into WebUtil?
Yes. WebUtil runs 100% client-side in your browser. No tokens, claims, or telemetry are ever sent across the network.
Where should JWT tokens be stored securely in web applications?
For web applications, storing JWTs in httpOnly, secure, sameSite cookies protects them from XSS attacks. Avoid storing sensitive tokens in localStorage or sessionStorage.