🏠 Home
CPS Test Aim Trainer Typing Speed Scroll Speed View All Games →
AI Image Generator Background Remover Social Media Cropper Youtube Thumbnails View All Images →
Word Counter Case Converter Invisible Text Text to Speech View All Text Tools →
JSON Formatter Diff Checker Base64 Converter Meta Tag Generator View All Dev Tools →
Unit Converter Age Calculator BMI Calculator Time Zone Converter View All Calculators →
Home / Blog / Decode JWT Guide

How to Decode a JWT Token (Header, Claims & Expiry)



Magnifying glass revealing token claims

It is 2am, logins are failing in staging, and the entire difference between shipping the fix and staring at the ceiling is one question: what is actually inside this token? I have been there more times than I will admit, squinting at eyJhbGciOi... like it might confess. JWTs look opaque but are barely encoded at all — two base64url JSON blobs you can read in seconds once you know the trick. This guide teaches the trick, and the free tool does it for you.

Anatomy of Three Dots

Every JWT is header.payload.signature — three base64url segments joined by dots. The header names the algorithm (HS256, RS256) and type. The payload carries claims: standard ones like iss (who issued it), sub (whose token), aud (who it is for), and the time trio iat/nbf/exp — plus whatever custom fields your auth server stuffed in. The signature proves nobody tampered with the first two, verifiable only with the secret or public key. Paste all three parts into our JWT Decoder and each layer unpacks into readable tables, with exp translated to a real date plus a live EXPIRED-or-valid badge.

The 2am Debugging Playbook

  1. Decode first, theorize later. Half of all "auth is broken" incidents are expired test tokens or tokens minted for the wrong audience — both visible in five seconds flat.
  2. Read exp against your clock. Short-lived staging tokens (looking at you, 5-minute lifetimes) die mid-debug-session. If exp is in the past, mint fresh before touching code.
  3. Check aud and iss. Tokens for the wrong environment or service fail with maddeningly generic 401s. The claims table spells out exactly who the token thinks it belongs to.
  4. Verify signature server-side. A decodable token is not a valid token — only your backend, holding the secret, can confirm integrity.
Pro Tip: Treat every token you paste anywhere as burned. Debugging with production tokens is like lockpicking your own front door on a livestream — use short-lived test tokens, then rotate anything real that touched a third party. Yes, including well-behaved decoders.

JWT FAQs

Can anyone read my JWT?

Anyone holding it, yes — payloads are encoded, not encrypted. Never put passwords, personal data, or anything sensitive in claims. If it must stay secret, it does not belong in a token.

Why does login fail with a valid-looking token?

Usual suspects in order: expired exp, wrong aud, clock skew between servers, revoked refresh chain, or a signature mismatch from key rotation. The decoder eliminates the first three in under a minute.

What is the difference between JWT and sessions?

Sessions store state on the server and hand the client an opaque ID; JWTs hand the client the state itself, signed. JWTs scale statelessly across services but cannot be individually revoked before expiry — the fundamental tradeoff driving the whole debate.

Staring at an eyJ blob right now? Decode it.

Decode JWT Free

Share This Tool

⭐
Enjoying NoLoginTool?

Save it for later access 🚀