Stax
Tools

JWT Decoder

Decode any JWT instantly — inspect the header, payload claims, and expiry with human-readable timestamps. 100% client-side; tokens never leave your browser.

How JWT works

A JSON Web Token, as defined in RFC 7519, has three Base64url-encoded sections separated by dots. The header specifies the signing algorithm (e.g., HS256, RS256). The payload contains claims — key-value pairs like user ID, roles, and expiry. The signature is created by signing the header and payload with a secret or private key, per the JSON Web Signature structure in RFC 7515.

Anyone can decode the header and payload without a key — they're just Base64url encoding, not encryption. Only the signature requires the key. This means sensitive data should never go in the payload unless the entire token is encrypted (JWE).

Common debugging uses

  • Check if a token is expired (exp claim)
  • Confirm which user or session a token belongs to (sub claim)
  • Inspect role or permission claims your API is reading
  • Debug authentication issues in development
  • Validate token structure before implementation

JWT security tips

  • Don't store sensitive data in the payload — it's not encrypted, just encoded.
  • Set short expiry times — 15 minutes to 1 hour for access tokens, longer for refresh tokens.
  • Use RS256 over HS256 in multi-service architectures — each service can verify without sharing the secret.
  • Validate the signature server-side — never trust a token the client modifies.

JWT vs session tokens — when to use each

JWTs are stateless — the server does not need to look up a session in a database to validate the token. This makes them ideal for microservices and APIs where multiple services need to authenticate the same user without sharing a session store. The downside is that JWTs cannot be immediately revoked: once issued, they are valid until they expire. For logout-on-demand functionality, you need a token revocation list or very short expiry times combined with refresh tokens.

Traditional session cookies are stored server-side: easy to revoke, but require a shared session store (Redis, database) that all services can access. Choose JWTs for stateless APIs and microservices; choose sessions for monolithic applications where immediate logout is a requirement.

Frequently asked questions

What is a JWT?
JWT (JSON Web Token) is an open standard (RFC 7519) for securely transmitting information as a JSON object. It consists of three parts separated by dots: a Header (algorithm), a Payload (claims), and a Signature. JWTs are commonly used for authentication and API authorization.
Is it safe to paste my JWT here?
Yes. This tool runs entirely in your browser — no data is sent to any server. That said, treat JWTs like passwords: avoid pasting production tokens from sensitive systems into public tools as general best practice. Use test tokens for debugging.
Can this verify the JWT signature?
No. Signature verification requires the secret key (for HMAC) or the public key (for RSA/ECDSA). Since this is a client-side tool, the secret is never available here. Decoding the payload is always possible without the key — which is why sensitive data should never be stored unencrypted in a JWT payload.
What are common JWT claims?
Standard claims include: sub (subject/user ID), iss (issuer), aud (audience), exp (expiry timestamp), iat (issued at), nbf (not before). Custom claims are anything else your application adds, like roles, permissions, or user metadata.
Can I decode a JWT without the secret key?
Yes — the header and payload are just base64url-encoded JSON, readable by anyone who holds the token. The secret key is only needed to VERIFY the signature (i.e., prove the token wasn't tampered with), not to read its contents. That's also why you should never put sensitive data inside a JWT payload.
Why does my JWT fail to decode?
A valid JWT is three base64url sections separated by dots: header.payload.signature. The usual culprits are a truncated copy-paste (check the token ends after the third section), surrounding quotes or a 'Bearer ' prefix pasted along with it, or line breaks introduced by an email client. Strip those and paste the bare token.

From the blog

Related tools