Token anatomy

A JWT is three chunks of text glued together with dots. This page pulls one apart, decodes it and explains what every claim means — entirely inside this tab, with no network requests of any kind.

The token

Decoding is not verifying. The first two parts are just text in disguise — anyone holding a token can read them, and this page did exactly that with plain JavaScript. Reading the claims tells you what a token says, never that it is genuine. Nothing you type here leaves the page.

time window no token Paste a token or pick a sample.
signature not checked Decoding never touches the signature.

part 1 of 3

Header

how the token was signed
decoded json
waiting for a token
    part 2 of 3

    Payload

    what the token claims
    decoded json
    waiting for a token
      part 3 of 3

      Signature

      the part you cannot read
      —
      characters— raw bytes— algorithm—

      The signature is a fingerprint of the first two parts. Change one character anywhere above and it stops matching.