JWT Parser
Decode and verify JSON Web Tokens (JWT) instantly. All processing is done in your browser for maximum security and privacy.
Header
Payload
Signature
Verification runs locally with the WebCrypto API. The key never leaves this page.
Invalid Token Structure
How to Use JWT Parser
Paste Your Token
Copy and paste your JWT into the input field above
Instant Decode
The token is automatically decoded to show header, payload, and signature
Analyse
Review the decoded information and check token validity
What is a JWT?
JSON Web Token (JWT) is an open standard (RFC 7519) that defines a compact and self-contained way for securely transmitting information between parties as a JSON object.
JWT Structure
A JWT consists of three parts separated by dots:
Header
Contains metadata about the token, such as the algorithm used for signing
Payload
Contains the claims or statements about an entity and additional metadata
Signature
Used to verify that the sender of the JWT is who it says it is and to ensure the message wasn't changed
Frequently Asked Questions
Yes, when using this tool. All processing is done 100% in your browser. Your tokens are never sent to any server. Please be cautious with other online tools that may send your tokens to their servers.
For HMAC-based tokens (HS256, etc.), you can verify the signature if you have the secret key. For RSA-based tokens (RS256, etc.), you need the public key. Note that this verification is done client-side for your convenience.
A JWT is expired when the current time exceeds the "exp" (expiration) claim in the payload. This tool shows you if a token is expired, active, or not yet valid based on these time claims.
You can modify the payload, but the signature will no longer be valid unless you have the signing key. This is the security mechanism of JWTs - any modification invalidates the signature.
"exp" (expiration) specifies when the token should stop being valid, while "nbf" (not before) specifies when the token starts being valid. For example, you might set "nbf" to create a token that becomes valid in the future.
No! JWT payload is base64 encoded, not encrypted. Anyone can decode and read the contents. Never include passwords, API keys, or other sensitive information in a JWT.
For production applications, use asymmetric algorithms like RS256 or ES256. Avoid using "none" algorithm as it provides no security. HS256 can be used but requires careful secret management.
JWT is designed to be decoded without any special tools. The header and payload are simply base64-encoded JSON. This tool uses JavaScript to decode and display them in your browser. No server communication is needed.
Related Tools
Authoritative References
Primary sources behind this tool - official standards and specifications, not secondhand summaries.
RFC 7519 - JSON Web Token (JWT)
The IETF standard that defines the JSON Web Token structure: header, payload, signature.
RFC 7515 - JSON Web Signature (JWS)
The companion standard covering JSON Web Signature — how JWT signatures are created and verified.
Introduction to JSON Web Tokens - jwt.io
The official introduction to JSON Web Tokens with interactive debugging, maintained by Auth0.
JSON Web Token - Wikipedia
Token structure, common claims (iss, sub, exp), and how JWTs are used for authentication.