Skip to content

JWT decoder

Paste a JSON Web Token to read its header and claims. It is decoded in your browser and never sent anywhere.

Algorithm: HS256Signature not verified
Subject (sub)
1234567890
Issued at (iat)
Thu, 18 Jan 2018 01:30:22 UTC

How it works

What's inside a JWT

A JSON Web Token has three parts separated by dots:

  • Header: which algorithm signed the token, such as HS256 or RS256.
  • Payload: the claims: who the token is about, who issued it, when it expires, and any custom data.
  • Signature: proof that the header and payload haven't been changed, made with a secret or private key.

The header and payload are just JSON encoded with URL-safe Base64, which is why this page can read them without any key. The signature is what makes a JWT trustworthy, and checking it is your server's job.

Common JWT mistakes

  • Trusting the payload without verifying the signature on the server.
  • Accepting the none algorithm, which means no signature at all.
  • Long or missing expiry times: a leaked token stays usable until it expires.
  • Storing personal data in the payload, which anyone holding the token can read.

More tools

More on the bench

  • JSON formatter and validatorPretty-print, minify and validate JSON, with the exact line of any error.
  • Base64 encoder and decoderEncode text to Base64 and back, including URL-safe Base64 and emoji.
  • URL encoder and decoderPercent-encode and decode URLs and query values, and break a URL into parts.
  • CSV to JSON converterConvert CSV to JSON and JSON to CSV, with delimiter detection.
  • UUID generatorGenerate random v4 or time-ordered v7 UUIDs, one or a hundred at a time.
  • Hash generatorSHA-1, SHA-256, SHA-384 and SHA-512 hashes of any text.

Frequently asked questions

Is it safe to paste my token here?

DevBenchr decodes the token in your browser and never sends it anywhere. Still, treat real tokens like passwords: they can give access to accounts. Prefer tokens from test environments, and never paste production tokens into tools that send them to a server.

Does the decoder check the signature?

No. Checking the signature needs the secret or public key, which shouldn't be pasted into a website. Decoding shows what a token claims; only your server, with the key, can confirm the claims are genuine.

Are JWTs encrypted?

Usually not. A standard JWT is only signed: anyone who has it can read the contents, as this page shows. Don't put secrets or sensitive personal data in a JWT payload unless it is encrypted (a JWE).

What do exp, iat and nbf mean?

They are timestamps in seconds since 1 January 1970 (UTC). exp is when the token expires, iat when it was issued, and nbf the moment before which it must not be accepted. DevBenchr turns them into dates.