What is a JWT?
A JSON Web Token (JWT, pronounced “jot”, RFC 7519) is a compact token that carries claims — such as a user ID, roles and an expiry time — as JSON. JWTs are used as OAuth 2.0 access tokens and OpenID Connect ID tokens, and by identity services such as Auth0, Firebase Authentication and Amazon Cognito.
A JWT has three parts separated by dots: header.payload.signature.
| Part | Contents |
|---|---|
| Header | The signing algorithm (alg, e.g. HS256, RS256) and token type (typ) |
| Payload | The claims: who the token is for, who issued it, when it expires, plus any custom data |
| Signature | Computed over the header and payload so the receiver can detect tampering |
The header and payload are only Base64url-encoded, not encrypted. Anyone holding the token can read them, so never put passwords or other secrets in the payload. For example, the header eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9 decodes to {"alg":"HS256","typ":"JWT"}.
Registered claims
| Claim | Meaning |
|---|---|
iss | Issuer — who created the token |
sub | Subject — usually the user ID |
aud | Audience — who the token is intended for |
exp | Expiration time, as a Unix timestamp in seconds |
nbf | Not before — the token is invalid before this time |
iat | Issued at — when the token was created |
jti | JWT ID — a unique identifier for the token |
This tool shows exp, nbf and iat as UTC and in your local time zone, flags expired or not-yet-valid tokens, and warns when alg is none (an unsigned token).
Decoding a JWT in code
To read the payload without verifying it — for debugging only — split on . and Base64url-decode the second part:
| Language | Decode payload (no verification) |
|---|---|
| Node.js | JSON.parse(Buffer.from(token.split('.')[1], 'base64url')) |
| Python (PyJWT) | jwt.decode(token, options={"verify_signature": False}) |
| Shell | cut -d. -f2 <<< "$TOKEN" | tr '_-' '/+' | base64 -d (add = padding if needed) |
In production, always verify the signature, exp, iss and aud with a maintained library such as jsonwebtoken or jose (Node.js), PyJWT (Python) or golang-jwt/jwt (Go).
Frequently asked questions
Is it safe to paste a production token?
This tool decodes the token in your browser and never sends it to a server. Still, a valid access token can be misused if leaked, so handle it carefully with any tool and clear it when you are done.
Does this tool verify the signature?
No. It only decodes and displays the contents. Verifying a signature requires the secret or public key and should be done with a JWT library on your server.
How do I debug a 401 Unauthorized error?
Check that exp has not passed, that nbf is not in the future, and that aud and iss match what the API expects. Also watch for clock skew between client and server.