ParseJar › Security

JWT Decoder

Paste a JSON Web Token to see its header and claims, when it was issued and whether it has expired. The token never leaves your browser.

What a JWT contains

A JWT is three Base64URL strings joined by dots: a header (algorithm and type), a payload (the claims) and a signature. The first two are only encoded, not encrypted, so anyone holding the token can read them, which is why this tool can decode them without a key. Don't put secrets in JWT claims.

Registered claims

  • exp: expiry, in Unix seconds. iat: issued at. nbf: not valid before.
  • iss: who issued it. sub: who it is about. aud: who it is meant for.

About verification

Decoding is not verification. For HMAC tokens (HS256/384/512) you can check the signature here with the shared secret, using the browser's Web Crypto API. Tokens signed with RS256 or ES256 need the issuer's public key (often from a JWKS URL) and should be verified in your backend with a maintained library.

FAQ

Is it safe to paste a production token?

The token is processed only in your browser and is not sent or stored. Still, treat live tokens like passwords; prefer an expired or test token when you can.

Why does it say alg "none" is dangerous?

A token with alg "none" has no signature. Libraries that accept it let anyone forge tokens. Your server should reject it.

ParseJar is free. Its sister project ScrapeMole sells pay-per-call data APIs for AI agents.

Related tools