Back to Tools
🔑

JWT Decoder

Security

Decode and inspect JSON Web Token expiration and payload details.

⚠️
Algorithm
-
Type
-
Issued At
-
Expires At
-
📋 Header

            
📦 Payload

            
🔐 Signature
About JWT

JWT (JSON Web Token) is an open standard (RFC 7519) for securely transmitting information between parties. JWT consists of three parts: Header, Payload, and Signature.

JWT Structure:

Header.Payload.Signature

// Example
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9
.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ
.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c

Standard Claims

Standard Claims:

  • iss - Issuer
  • sub - Subject
  • aud - Audience
  • exp - Expiration Time
  • nbf - Not Before
  • iat - Issued At
  • jti - JWT ID

Security Tips

Security Notes:

  • Do not store sensitive information in JWT. Payload can be decoded by anyone.
  • Always verify the signature to ensure the token has not been tampered with.
  • Check expiration time and reject expired tokens.
  • Use HTTPS to prevent token interception.
  • Do not store tokens in localStorage. Use httpOnly cookies.