JWT Online Decoder
Parse a JWT token / Header / Payload / Expiry check
{
"alg": "HS256",
"typ": "JWT"
}{
"sub": "demo-001",
"name": "简美工具",
"iat": 1782869463
}What is JWT?
JWT (JSON Web Token) is a compact, URL-safe token format made up of three parts: Header.Payload.Signature. This tool only decodes and does not verify the signature. To inspect the Base64URL structure of the Header and Payload, pair it with the Base64 encoder/decoder.
FAQ
What is JWT and what are its parts?
JWT (JSON Web Token) is a compact token format used for authentication, made up of three parts: Header (algorithm and type), Payload (user info and claims) and Signature (used to verify the token has not been tampered with). The three parts are separated by dots and each is Base64URL-encoded.
What is the difference between decoding and verifying the signature?
This tool Base64URL-decodes the JWT Header and Payload to show the information inside; it does not verify the signature. Verification requires a server-side secret (an HMAC key or RSA public key) and cannot be done from the token alone. To check expiry, the tool parses the exp claim and compares it with the current time.
Is the decoded data safe?
All decoding runs locally in your browser; the JWT token is never uploaded to any server. Note, however: do not expose a token containing sensitive information in public or in screenshots, because the Header and Payload are Base64-encoded (not encrypted) and anyone can decode and read them.
What common registered claims does JWT have?
Common registered claims include: iss (issuer), sub (subject/user ID), aud (audience), exp (expiration time), iat (issued at), nbf (not before) and jti (unique ID). Among them exp is used to check expiry and is one of the most commonly used claims.