Skip to the decoder

What is a JWT?

A JSON Web Token is a signed note from a server that other services can trust without phoning home. Here is how it works, in plain English, with a decoder to poke at.

Three parts, two readable

A JWT is three chunks of base64url text joined by dots: header.payload.signature. The header says which algorithm signed it. The payload carries the claims: who you are (sub), who issued it (iss), who it is for (aud) and the time window (iat, nbf, exp). The signature is computed over the first two parts with a key only the issuer holds.

The crucial mental model: encoded is not encrypted. Anyone holding the token can read the header and payload, as the decoder below demonstrates. What they cannot do is change a single character without the signature failing verification. Signing gives integrity and authenticity, never secrecy, so a payload must never carry passwords or private data.

Why systems use them

Classic sessions store state on the server and hand the browser a reference. A JWT flips that: the state travels with the request, and any service holding the verification key can check it locally. That is why they power APIs, microservices and single sign-on. The trade-off is that a token, once issued, is valid until it expires, which is why lifetimes are short and why the exp claim matters so much (the expiry checker exists for exactly that claim).

Try it: decode a token

The sharp edges

Mistakes that keep security teams busy

Secrets in the payload

Payloads are readable by design. Personal data, card details or passwords inside a token are exposed to every system, log and browser extension that ever touches it.

Trusting without verifying

Decoding is not verification. A server that reads claims without checking the signature will accept any token an attacker types, including alg none tokens.

Weak HS256 secrets

A guessable shared secret lets attackers mint their own valid tokens. Secrets should be long and random, the generator at 64 characters is right for the job.

FAQ

Frequently asked questions

What is a JWT in one sentence?

A JSON Web Token is a signed note from a server: a small JSON document (who you are, what you may do, until when) encoded into a portable string that any service holding the key can verify without a database lookup.

Is a JWT encrypted?

The common kind, a JWS, is signed but not encrypted: anyone holding it can read it, and the signature only proves it was not altered. Encrypted JWTs (JWE) exist but are rarer.

Where should a web app store its JWT?

The safest common answer is an HttpOnly, Secure cookie, which JavaScript cannot read and therefore cross-site scripting cannot steal. localStorage is convenient but readable by any script that runs on your page.

What is the difference between HS256 and RS256?

HS256 signs with a shared secret, so every verifier can also mint tokens. RS256 signs with a private key and verifies with a public one, so services can check tokens they could never forge. Multi-service systems usually want RS256.

Can a JWT be revoked?

Not by itself, statelessness cuts both ways. Systems that need revocation keep a deny list, rotate keys or keep token lifetimes short enough that revocation barely matters.

Why did JWTs become so popular?

They let services verify identity without calling a central session store, which suits APIs, microservices and single sign-on. The cost is care: signing keys, expiry and storage all have to be handled properly.

More tools

Related tools

JWT decoderThe standalone decoder with the full claims table. JWT expiry checkerA live countdown on the exp claim. Base64 decodeDecode a JWT segment by hand and see the JSON.
Skip to the decoder

What is a JWT?

A JSON Web Token is a signed note from a server that other services can trust without phoning home. Here is how it works, in plain English, with a decoder to poke at.

Three parts, two readable

A JWT is three chunks of base64url text joined by dots: header.payload.signature. The header says which algorithm signed it. The payload carries the claims: who you are (sub), who issued it (iss), who it is for (aud) and the time window (iat, nbf, exp). The signature is computed over the first two parts with a key only the issuer holds.

The crucial mental model: encoded is not encrypted. Anyone holding the token can read the header and payload, as the decoder below demonstrates. What they cannot do is change a single character without the signature failing verification. Signing gives integrity and authenticity, never secrecy, so a payload must never carry passwords or private data.

Why systems use them

Classic sessions store state on the server and hand the browser a reference. A JWT flips that: the state travels with the request, and any service holding the verification key can check it locally. That is why they power APIs, microservices and single sign-on. The trade-off is that a token, once issued, is valid until it expires, which is why lifetimes are short and why the exp claim matters so much (the expiry checker exists for exactly that claim).

Try it: decode a token

Decode only.

The signature is NOT verified, so treat the contents as claims, not facts. The token never leaves your browser.

Paste a token to read its header and payload.

Everything runs in your browser. Tokens are decoded on your device and never transmitted or logged.

The sharp edges

Mistakes that keep security teams busy

Secrets in the payload

Payloads are readable by design. Personal data, card details or passwords inside a token are exposed to every system, log and browser extension that ever touches it.

Trusting without verifying

Decoding is not verification. A server that reads claims without checking the signature will accept any token an attacker types, including alg none tokens.

Weak HS256 secrets

A guessable shared secret lets attackers mint their own valid tokens. Secrets should be long and random, the generator at 64 characters is right for the job.

FAQ

Frequently asked questions

What is a JWT in one sentence?

A JSON Web Token is a signed note from a server: a small JSON document (who you are, what you may do, until when) encoded into a portable string that any service holding the key can verify without a database lookup.

Is a JWT encrypted?

The common kind, a JWS, is signed but not encrypted: anyone holding it can read it, and the signature only proves it was not altered. Encrypted JWTs (JWE) exist but are rarer.

Where should a web app store its JWT?

The safest common answer is an HttpOnly, Secure cookie, which JavaScript cannot read and therefore cross-site scripting cannot steal. localStorage is convenient but readable by any script that runs on your page.

What is the difference between HS256 and RS256?

HS256 signs with a shared secret, so every verifier can also mint tokens. RS256 signs with a private key and verifies with a public one, so services can check tokens they could never forge. Multi-service systems usually want RS256.

Can a JWT be revoked?

Not by itself, statelessness cuts both ways. Systems that need revocation keep a deny list, rotate keys or keep token lifetimes short enough that revocation barely matters.

Why did JWTs become so popular?

They let services verify identity without calling a central session store, which suits APIs, microservices and single sign-on. The cost is care: signing keys, expiry and storage all have to be handled properly.

More tools

Related tools