What a JWT contains
A JWT is three Base64URL strings joined by dots: a header (algorithm and type), a payload (the claims) and a signature. The first two are only encoded, not encrypted, so anyone holding the token can read them, which is why this tool can decode them without a key. Don't put secrets in JWT claims.
Registered claims
exp: expiry, in Unix seconds.iat: issued at.nbf: not valid before.iss: who issued it.sub: who it is about.aud: who it is meant for.
About verification
Decoding is not verification. For HMAC tokens (HS256/384/512) you can check the signature here with the shared secret, using the browser's Web Crypto API. Tokens signed with RS256 or ES256 need the issuer's public key (often from a JWKS URL) and should be verified in your backend with a maintained library.
FAQ
Is it safe to paste a production token?
The token is processed only in your browser and is not sent or stored. Still, treat live tokens like passwords; prefer an expired or test token when you can.
Why does it say alg "none" is dangerous?
A token with alg "none" has no signature. Libraries that accept it let anyone forge tokens. Your server should reject it.