What is inside a JWT
A JSON Web Token is three pieces of text joined by dots. The first is the header, which names the signing algorithm. The second is the payload with the claims: who the user is, who issued the token and when it expires. The third is the signature over the first two. Header and payload are only Base64url encoded, so this JWT decoder, like any other, can read them without a key. That is why a token should never carry passwords or other secrets in its payload. Unlike many online decoders, this one does all the work in your browser, so a live token from production never travels to someone else's server.
The registered claims
RFC 7519 defines seven short claim names. The decoder shows each one it finds with its meaning, and turns the three time claims into dates in your time zone.
| Claim | Name | What it means |
|---|---|---|
| iss | Issuer | Who created and signed the token, often the URL of the login server. |
| sub | Subject | Whom the token is about, usually a user ID. |
| aud | Audience | The service the token is meant for. An API should reject tokens with another audience. |
| exp | Expiration time | After this moment the token must be rejected. Seconds since 1970 (Unix time). |
| nbf | Not before | The token is not valid before this moment. |
| iat | Issued at | When the token was created. |
| jti | JWT ID | A unique ID, used to stop the same token from being replayed. |
Checking the signature
For HS256, HS384 and HS512 the issuer and the API share one secret, and the check recomputes the HMAC with it. For RS, PS and ES algorithms the issuer signs with a private key and anyone can verify with the public key, often published at a JWKS address such as /.well-known/jwks.json. Paste one key from that list as JWK, or the PEM public key. All checks use the WebCrypto functions built into your browser.
A valid signature plus a future exp is what an API checks before it trusts a token. If you are debugging a login, also compare aud and iss with what your server expects; a mismatch there is a frequent cause of 401 errors. To turn a raw exp value into a date for a log or ticket, the Unix timestamp converter does the same conversion for any number.
Debugging a bearer token
- 1Copy the Authorization header value from your browser's network tab or your API client and paste it, Bearer prefix and all.
- 2Read the status line first: it tells you at a glance whether the token has expired or is not valid yet.
- 3Enter the secret or public key from the environment that issued the token to confirm the signature, then compare the claims with what your API expects.
Frequently asked questions
Is it safe to paste my token here?
The decoder runs entirely in your browser: the token, the secret and the public key are never sent anywhere, and the page has no share link that would put them in a URL. Still treat a valid production token like a password, because anyone who has it can use it until it expires.
Does decoding a JWT prove it is valid?
No. Anyone can decode a JWT, because the header and payload are only Base64url encoded, not encrypted. Only the signature check proves that the token was issued by someone who holds the secret or private key and that nobody changed it.
Why does the signature check fail?
Common causes are the wrong secret, a secret that is really Base64 encoded (tick the Base64 box), a public key from another environment, or a token that was edited after signing. A single changed character in the header or payload breaks the signature.
Which algorithms can it verify?
HS256, HS384 and HS512 with a shared secret, and RS256, RS384, RS512, PS256, PS384, PS512, ES256, ES384 and ES512 with a public key in PEM (BEGIN PUBLIC KEY) or JWK format. Tokens with alg set to none have no signature, and servers should refuse them.
What is the difference between a JWT and Base64?
A JWT is three Base64url parts joined by dots: a JSON header, a JSON payload with the claims, and a signature. Decoding the first two parts with a Base64 decoder shows the same JSON this tool shows, but without the claim dates, the expiry check and the signature check.