JWT Decoder
Decode and inspect JWT tokens. View header, payload claims, expiration, and algorithm. Signature verification requires the secret key and is not performed here.
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c2VyXzEyMyIsIm5hbWUiOiJBbGljZSIsImVtYWlsIjoiYWxpY2VAeXVybGllLmNvbSIsInJvbGUiOiJ1c2VyIiwiaWF0IjoxNzAwMDAwMDAwLCJleHAiOjk5OTk5OTk5OTl9.example_signature
HeaderPayloadSignature
ClaimValueDescription
sub"user_123"name"Alice"email"alice@yurlie.com"role"user"iat1700000000Nov 14, 2023, 10:13:20 PM UTCexp9999999999Nov 20, 2286, 05:46:39 PM UTCSignature verification requires the secret key and is not performed in the browser. This tool is for decoding and inspecting only.
What is a JWT?
A JSON Web Token (JWT) is a compact, URL-safe token format defined in RFC 7519. It consists of three Base64url-encoded parts separated by dots:header.payload.signature.
- Header: Specifies the algorithm (
HS256,RS256, etc.) and token type (JWT) - Payload: Contains claims — statements about the user and metadata (
sub,iat,exp, custom claims) - Signature: Cryptographic hash that verifies the token has not been tampered with
Standard JWT Claims
| Claim | Full Name | Description |
|---|---|---|
iss | Issuer | Who created and signed the token |
sub | Subject | The principal (user) the token identifies |
aud | Audience | Intended recipient of the token |
exp | Expiration Time | Unix timestamp after which the token is invalid |
nbf | Not Before | Unix timestamp before which the token is invalid |
iat | Issued At | Unix timestamp when the token was created |
jti | JWT ID | Unique identifier to prevent token replay |
JWT Security Best Practices
- Always validate
exp: Reject expired tokens to limit the window of a compromised token - Validate
issandaud: Ensure the token was issued by your auth server and intended for your service - Use short expiration times: Access tokens should expire in 5–15 minutes. Use refresh tokens for longer sessions
- Never store secrets in the payload: JWTs are encoded, not encrypted — anyone can decode the payload
- Enforce the algorithm: Always validate that the
algheader matches your expected algorithm to prevent algorithm confusion attacks