What Is a JWT and How to Read It
4 min read
A JWT, or JSON Web Token, is a compact string of three parts separated by dots: a header, a payload and a signature. The header says how the token was signed, the payload carries the information, called claims, and the signature lets a server check that nobody changed it. You can read the first two parts with the JWT decoder in seconds.
The most important thing to know is that a JWT is encoded, not encrypted. Anyone who holds the token can read it, so decoding tells you what it says, not whether it can be trusted. This guide shows how to read a token and what to check.
Steps
Use a token from your own project or a test token. Avoid pasting live production tokens into tools you do not control. The decoder on this site works entirely in your browser.
- 1
Paste the token
Open the JWT decoder and paste the token. A leading “Bearer ” from an Authorization header is removed for you. A normal JWT looks like three Base64URL chunks: xxxxx.yyyyy.zzzzz.
- 2
Read the header
The header is a small JSON object. alg is the signing algorithm, such as HS256 (a shared secret) or RS256 and ES256 (a private and public key pair), and typ is usually JWT. If alg says none, the token is unsigned and should not be trusted.
- 3
Read the payload
The payload holds claims: pieces of information about the user and the token. Some names are standard, and the tool explains them in plain language. Everything else is up to the application that issued the token.
- 4
Check the times
exp is when the token expires, nbf is when it becomes valid and iat is when it was issued, all as Unix time in seconds. The decoder converts them to your local date and says whether the token is expired or not active yet.
- 5
Verify the signature
If you have the secret (for HS256, HS384 or HS512) or the public key (for RS or ES algorithms), paste it into the verification box. The tool checks the signature locally with your browser’s crypto and reports valid, invalid or not checked.
- 6
Check who it is for
Compare iss (who issued it) and aud (who it is meant for) with what your application expects. A valid signature on a token meant for a different service is still the wrong token.
The standard claims in one list
iss is the issuer, sub is the subject (often a user id), aud is the audience, exp is the expiry time, nbf is “not before”, iat is “issued at” and jti is a unique token id. Applications add their own claims, such as a name, a role or a tenant. Arabic and other Unicode text in claims is fine, because the payload is UTF-8 JSON.
Encoding is not encryption
Base64URL only changes how bytes are written so that they fit in a URL or a header. It hides nothing. Never put passwords, card numbers or other secrets in a JWT payload. If the content must stay private, it needs encryption (a different format called JWE, which has five parts) or should stay on the server.
Habits that keep tokens safe
Always verify the signature on the server and check exp, iss and aud before trusting a token. Keep lifetimes short and use refresh tokens for long sessions. Choose the algorithm on the server instead of trusting the header, and reject alg none. Store tokens carefully and never log them. When you need to inspect a token, use a tool that runs locally, like this one, which sends nothing anywhere.
Common problems
The decoder says the signature is invalid
Common causes are the wrong secret or key, a key in the wrong format, an extra space or line break, or a mismatch between the key type and the alg in the header. Paste the key exactly as issued.
The token shows as expired
Its exp time is in the past. Request a new token. If it looks expired right after issue, compare your computer’s clock with the server’s, since clock skew can cause this.
The token has five parts or will not decode
Five parts usually means an encrypted JWE token, which cannot be read without the decryption key. Check also that you copied the whole string without quotes or spaces.
The payload shows strange characters
The payload must be UTF-8 JSON. If an application encoded text in another way, the characters will look wrong. Arabic text encoded correctly shows normally.
Frequently asked questions
What does a JWT contain?
A header with the algorithm, a payload with claims such as the user id and expiry, and a signature. The first two parts are readable by anyone who has the token.
Is it safe to decode a JWT online?
Only if the tool works locally. The JWT decoder here runs in your browser and sends nothing to a server. Still avoid pasting live production tokens anywhere you do not control.
Does decoding a JWT prove it is valid?
No. Decoding only reads it. Validity needs a signature check with the right key, plus checks on the expiry, issuer and audience.
Related guides
- How to Choose Colors for Your Website or ProjectA practical way to pick a palette that looks good and stays readable.
- Best Free Arabic Fonts for DesignA curated guide to free Arabic fonts by style and use, with what each is good for.
- How to Make a Favicon for Your WebsiteCreate every icon a site needs and add it to your pages in a few minutes.