jwt.cs

JWT Decoder

Decode JSON Web Tokens online and inspect JWT headers and payloads in a readable format. A quick and simple JWT debugging tool for developers.

JWT Decoder

Everything you enter is processed in your browser.

Signature unverified. Decoding a token does not establish that it is authentic or valid.

JWT Decoder

Decode JSON Web Tokens (JWTs) and inspect their contents in a clear, readable format.

Paste a JWT into the decoder to view its header and payload, making it easier to debug authentication, authorization and API integrations.

What is a JWT?

A JSON Web Token, commonly known as a JWT, is a compact format used to securely transmit information between systems.

JWTs are commonly used by web applications and APIs for authentication and authorization.

A JWT typically consists of three sections separated by periods:

header.payload.signature

For example:

eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjM0NTY3ODkwIn0.signature

What’s inside a JWT?

A typical JWT contains three components:

  • Header – describes the token type and signing algorithm
  • Payload – contains claims and information associated with the token
  • Signature – allows the recipient to verify that the token has not been modified

The header and payload are Base64URL encoded, which means they can be decoded and inspected without access to the signing key.

Common JWT claims

JWT payloads can contain almost any information, but several standard claims are commonly encountered:

  • sub – Subject or identifier associated with the token
  • iss – Token issuer
  • aud – Intended audience
  • exp – Expiration time
  • iat – Time the token was issued
  • nbf – Time before which the token should not be accepted
  • jti – Unique identifier for the token

Applications can also include their own custom claims.

Why decode a JWT?

Decoding a JWT can be useful when working with:

  • API authentication
  • OAuth and OpenID Connect
  • Identity providers
  • Access and ID tokens
  • Application authorization
  • User claims
  • Token expiration problems
  • Authentication debugging

It provides a quick way to understand exactly what information has been included within a token.

Decoding is not verification

Decoding a JWT does not verify that the token is genuine.

The header and payload of most JWTs are encoded rather than encrypted, so their contents can be read without validating the signature.

Applications should always perform proper signature validation before trusting the claims contained within a JWT.

Be careful with sensitive tokens

JWTs can contain sensitive information and may provide access to applications or APIs.

Avoid sharing active access tokens with other people or pasting production credentials into tools you do not trust. Where possible, use expired, development or test tokens when debugging authentication problems.

metrics.json
< metrics />

Our Stats

A snapshot of the experience, technology and work behind what we do.

experience
10+
Years Experience
projects
100+
Projects Delivered
technologies
25+
Technologies
success
99%
Placeholder Metric
metrics loaded
4 records
news.md
<articles />

News

Get our latest articles, ideas and technology insights delivered directly to your inbox.

$ subscribe

Read our Privacy Policy to learn how we handle personal information and how to contact us about your rights.

1 articles
news/