JWT Decoder

Decode and inspect JWT tokens. View header, payload claims, expiration, and algorithm. Signature verification requires the secret key and is not performed here.

Algorithm HS256Type JWT✓ Valid — expires in 2280347h 25m (Nov 20, 2286, 05:46:39 PM UTC)
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c2VyXzEyMyIsIm5hbWUiOiJBbGljZSIsImVtYWlsIjoiYWxpY2VAeXVybGllLmNvbSIsInJvbGUiOiJ1c2VyIiwiaWF0IjoxNzAwMDAwMDAwLCJleHAiOjk5OTk5OTk5OTl9.example_signature
HeaderPayloadSignature
ClaimValueDescription
sub
"user_123"
Subject — who the token refers to
name
"Alice"
Full name
email
"alice@yurlie.com"
Email address
role
"user"
Role
iat
1700000000Nov 14, 2023, 10:13:20 PM UTC
Issued at (Unix)
exp
9999999999Nov 20, 2286, 05:46:39 PM UTC
Expiration time (Unix)
Signature verification requires the secret key and is not performed in the browser. This tool is for decoding and inspecting only.

What is a JWT?

A JSON Web Token (JWT) is a compact, URL-safe token format defined in RFC 7519. It consists of three Base64url-encoded parts separated by dots:header.payload.signature.

  • Header: Specifies the algorithm (HS256, RS256, etc.) and token type (JWT)
  • Payload: Contains claims — statements about the user and metadata (sub, iat, exp, custom claims)
  • Signature: Cryptographic hash that verifies the token has not been tampered with

Standard JWT Claims

ClaimFull NameDescription
issIssuerWho created and signed the token
subSubjectThe principal (user) the token identifies
audAudienceIntended recipient of the token
expExpiration TimeUnix timestamp after which the token is invalid
nbfNot BeforeUnix timestamp before which the token is invalid
iatIssued AtUnix timestamp when the token was created
jtiJWT IDUnique identifier to prevent token replay

JWT Security Best Practices

  • Always validate exp: Reject expired tokens to limit the window of a compromised token
  • Validate iss and aud: Ensure the token was issued by your auth server and intended for your service
  • Use short expiration times: Access tokens should expire in 5–15 minutes. Use refresh tokens for longer sessions
  • Never store secrets in the payload: JWTs are encoded, not encrypted — anyone can decode the payload
  • Enforce the algorithm: Always validate that the alg header matches your expected algorithm to prevent algorithm confusion attacks