What is in a JSON Web Token
A JSON Web Token (JWT, pronounced "jot") is a compact string that servers hand to clients to prove who they are. It has three parts separated by dots. The first is the header, a small JSON object naming the signing algorithm and token type. The second is the payload, a JSON object of claims such as the subject (sub), the issuer (iss), the audience (aud), when it was issued (iat), when it starts being valid (nbf) and when it expires (exp). The third is the signature. The first two parts are only Base64URL-encoded, which is why anyone holding the token can read them, as this tool does.
What the decoder shows
The tool splits the token, converts the first two parts from Base64URL into text, parses them as JSON and prints them formatted. For the standard time claims, which are stored as seconds since 1 January 1970, it converts the numbers to readable UTC dates and tells you whether the token has already expired compared with your device clock. Custom claims, such as roles or tenant IDs, are shown exactly as they appear.
Decoding is not verifying
This is the most important point. Reading a token does not prove it is genuine. Only the server holding the secret key (or the public key for RSA and ECDSA algorithms) can verify the signature, and this tool does not attempt to. Never trust claims in a token you have not verified. Likewise, because payloads are readable, you should not place secrets such as passwords in a JWT.
Debugging tips
- If you copied the value from an Authorization header, the "Bearer " prefix is removed automatically.
- An "alg": "none" header is a warning sign. Properly configured servers reject unsigned tokens.
- Clock differences between servers can make a fresh token look "not yet valid" or expired by a few seconds.
- Encrypted tokens (JWE) have five parts and cannot be read without the key. This tool will report that it cannot decode them.
Privacy
Decoding is done locally in the page. Even so, treat live tokens as passwords: a valid access token lets someone act as you until it expires. Prefer expired or test tokens when you can.