What is a JWT?
A JSON Web Token is a compact, signed string used for logins and API access.
It has three parts separated by dots: the header (algorithm), the payload (claims such as user ID and expiry) and the signature. The first two are only encoded, not encrypted.
Common JWT claims
| Claim | Meaning |
|---|---|
iss | Issuer - who created the token |
sub | Subject - usually the user ID |
aud | Audience - which service the token is for |
exp | Expiry time |
iat | Issued-at time |
nbf | Not valid before this time |
jti | Unique token ID, used to block replay |
JWT security checklist
- Reject
alg: noneand pin the algorithms your server accepts. - Keep access tokens short-lived (minutes, not days).
- Never put passwords or personal data in the payload.
- Use long random secrets for HS256 - generate one with the Password Generator.
Working with encoded data? The Base64 Encoder / Decoder handles Base64URL too.
Frequently asked questions
Is it safe to paste a JWT here?
The token is decoded in your browser and never sent anywhere. Still, treat a live token like a password: anyone who has it can use it until it expires. Prefer expired or test tokens.
Does decoding verify the signature?
No. Decoding only reads the header and payload, which are just Base64URL-encoded JSON. Verifying the signature needs the secret or public key and must happen on your server.
Why is "alg: none" dangerous?
A token with alg: none has no signature at all. If a server accepts it, anyone can forge tokens. Servers must reject it and only allow the algorithms they expect.
What do exp, iat and nbf mean?
exp is when the token expires, iat when it was issued and nbf the earliest time it is valid. All are Unix timestamps - this tool converts them to readable dates.
Can I put sensitive data in a JWT?
Not in a normal signed JWT - its payload is readable by anyone, as this tool shows. Store only identifiers and permissions, or use an encrypted JWE.