Token anatomy
A JWT is three chunks of text glued together with dots. This page pulls one apart, decodes it and explains what every claim means — entirely inside this tab, with no network requests of any kind.
The token
Decoding is not verifying. The first two parts are just text in disguise — anyone holding a token can read them, and this page did exactly that with plain JavaScript. Reading the claims tells you what a token says, never that it is genuine. Nothing you type here leaves the page.
time window
no token
Paste a token or pick a sample.
signature
not checked
Decoding never touches the signature.
part 1 of 3
Header
how the token was signedwaiting for a token
part 2 of 3
Payload
what the token claimswaiting for a token
part 3 of 3
Signature
the part you cannot read—
characters—
raw bytes—
algorithm—
The signature is a fingerprint of the first two parts. Change one character anywhere above and it stops matching.
The samples on this page were signed in your browser with rosewood-demo-secret. Try it, then change one letter.
waiting for a secret