JWT Parser

Decode and verify JSON Web Tokens (JWT) instantly. All processing is done in your browser for maximum security and privacy.

100% Client-Side Instant Decode Detailed View
Decoded locally in your browser — your token never leaves your device

How to Use JWT Parser

1

Paste Your Token

Copy and paste your JWT into the input field above

2

Instant Decode

The token is automatically decoded to show header, payload, and signature

3

Analyse

Review the decoded information and check token validity

What is a JWT?

JSON Web Token (JWT) is an open standard (RFC 7519) that defines a compact and self-contained way for securely transmitting information between parties as a JSON object.

JWT Structure

A JWT consists of three parts separated by dots:

Header

Contains metadata about the token, such as the algorithm used for signing

Payload

Contains the claims or statements about an entity and additional metadata

Signature

Used to verify that the sender of the JWT is who it says it is and to ensure the message wasn't changed

Frequently Asked Questions

Is it safe to decode JWTs online?

Yes, when using this tool. All processing is done 100% in your browser. Your tokens are never sent to any server. Please be cautious with other online tools that may send your tokens to their servers.

Can I verify JWT signatures?

For HMAC-based tokens (HS256, etc.), you can verify the signature if you have the secret key. For RSA-based tokens (RS256, etc.), you need the public key. Note that this verification is done client-side for your convenience.

What makes a JWT expired?

A JWT is expired when the current time exceeds the "exp" (expiration) claim in the payload. This tool shows you if a token is expired, active, or not yet valid based on these time claims.

Why can't I modify a JWT?

You can modify the payload, but the signature will no longer be valid unless you have the signing key. This is the security mechanism of JWTs - any modification invalidates the signature.

What is the difference between "exp" and "nbf" claims?

"exp" (expiration) specifies when the token should stop being valid, while "nbf" (not before) specifies when the token starts being valid. For example, you might set "nbf" to create a token that becomes valid in the future.

Should I include sensitive data in JWT?

No! JWT payload is base64 encoded, not encrypted. Anyone can decode and read the contents. Never include passwords, API keys, or other sensitive information in a JWT.

What algorithms should I use?

For production applications, use asymmetric algorithms like RS256 or ES256. Avoid using "none" algorithm as it provides no security. HS256 can be used but requires careful secret management.

How does client-side decoding work?

JWT is designed to be decoded without any special tools. The header and payload are simply base64-encoded JSON. This tool uses JavaScript to decode and display them in your browser. No server communication is needed.

{-- * External Resources Component(#18 Phase 3b 内容佐证工程) * 工具页「权威引用」区块:RFC / W3C / WHATWG / ECMA / IANA / 官方规范站 / Wikipedia。 * * - 接受 :slug 属性 → 经 config/tool-sources.php 家族矩阵渲染该工具的权威引用 * - slug 未命中映射时不渲染(无权威来源的工具静默跳过) * - 链接 title 保持英文(引用源专名);description 经 * common.resources.descriptions.{key} 本地化,lang 未命中回退英文(线上不裸奔) * - 链接保持 dofollow(rel="noopener noreferrer") * * @param string|null $slug --}}