JWT Decoder
Decode JWT header and payload, inspect claims and expiry, and spot common security flaws. Runs locally, your tokens are never transmitted.
Last reviewed by the Radiatus Cloud team
JWT Decoder
Decode and debug JSON Web Tokens (JWT) to view their payload.
{}
{}
Need this handled by experts?
Radiatus runs VAPT, managed SOC & security engineering for regulated teams.
Structure
A JSON Web Token has three Base64url-encoded segments separated by dots: a header naming the signing algorithm, a payload of claims, and a signature over the first two. The header and payload are encoded, not encrypted. Anyone holding the token can read every claim in it. The signature does not hide the contents; it only proves they have not been altered.
Never put secrets in a payload
Because the payload is readable by anyone who intercepts or is issued the token, it must not carry anything confidential: no passwords, no full personal records, no internal credentials. A surprising number of production tokens contain email addresses, roles and internal identifiers the holder was never meant to see. Decode your own and check.
Registered claims worth knowing
exp is the expiry as a Unix timestamp and must be validated on every request. iat is issued-at and nbf is not-before. iss identifies the issuer and aud the intended audience; both must be checked, otherwise a valid token minted for a different service will be accepted by yours. sub identifies the subject and jti gives the token a unique ID, which is what makes selective revocation possible.
The alg:none attack
The specification permits an alg value of none, meaning unsigned. A verifier that reads the algorithm from the token's own header and trusts it can be handed a token with the signature stripped and alg set to none, and will accept forged claims. The related confusion attack swaps RS256 for HS256 so the verifier uses the public key as an HMAC secret. Both are avoided the same way: pin the expected algorithm server-side and reject anything else. Never let the token tell you how to verify it.
Revocation is the hard part
A signed JWT is valid until it expires and there is no built-in way to revoke one, so a stolen token remains usable for its full lifetime. That argues for short expiry on access tokens, typically minutes, with a longer-lived refresh token that can be revoked because it is checked against server state. Long-lived access tokens are convenient and are the reason JWT compromises tend to be severe.
This decoder does not verify
Decoding shows you what a token says. Verifying proves it is genuine, which requires the signing key. This tool decodes and inspects locally, and flags an expired token, a missing expiry, an alg of none, and an unusually long lifetime. Nothing is sent anywhere, which matters because a JWT is a live credential.
Related tools
- Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
- Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
- Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
- Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.
Frequently Asked Questions
Is a JWT encrypted?
No. The header and payload are Base64url encoded, which is trivially reversible. Anyone holding the token can read every claim. The signature protects integrity, not confidentiality. If you need the contents hidden, use JWE rather than a plain signed JWT.
Can I put user data in a JWT payload?
Only data the token holder is allowed to see, and only what your service actually needs. Identifiers and roles are normal. Full personal records and anything secret should stay server-side.
What is the alg:none vulnerability?
The spec allows an algorithm value of none, meaning unsigned. A verifier that trusts the token's own header can be handed a stripped-signature token with forged claims and accept it. Always pin the expected algorithm on the server and reject anything else.
How do I revoke a JWT?
You largely cannot, which is the format's main operational drawback. A signed token is valid until it expires. The standard mitigation is short-lived access tokens paired with a revocable refresh token, plus a denylist of jti values for emergencies.
Does this tool verify the signature?
No, it decodes and inspects. Verification needs the signing key, and pasting a production signing secret into any web tool would be a serious mistake. The decoder flags expiry, missing exp, alg of none and excessive lifetime.
Why does my JWT fail in a standard Base64 decoder?
JWTs use URL-safe Base64: - and _ instead of + and /, with padding removed. A standard decoder rejects it. Convert the characters back and re-add padding, or use a decoder that handles the URL-safe variant.
Privacy & Security
Tokens are decoded locally. We do not store your tokens.
How to Use
Paste your JWT string to see the Header and Payload decoded instantly.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Password Strength Checker
SecurityMeasure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
Password Generator
SecurityGenerate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
Hash Generator
SecurityGenerate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.