What is a JWT?+
A JSON Web Token (RFC 7519) is a compact way to pass claims between two parties: three base64url segments joined by dots. The header names the algorithm, the payload holds the claims (who the token is about, who issued it, who it is for, and when it expires), and the signature lets the receiver check that the first two were produced by someone holding the right key and have not been changed. JWTs are most often used as OAuth access tokens and OpenID Connect ID tokens.
How do I decode a JWT?+
Split it at the dots, base64url-decode the first two segments, and parse each result as JSON. That is all decoding is, which is why it needs no key. Paste a token into the box above and it happens as you type. base64url is ordinary Base64 with hyphen and underscore in place of plus and slash, and with the trailing equals signs removed, so a standard Base64 decoder needs those two characters swapped back first.
Is it safe to decode a JWT online?+
Only on a page that decodes it locally. A JWT is a bearer credential: whoever holds an unexpired one can usually use it. This page decodes and verifies in your browser and never sends the token anywhere, and you can check that yourself by opening the Network tab in your browser's developer tools before you paste. Even so, prefer expired or test tokens when you can, and never paste a production signing secret or a private key into any site you cannot inspect.
Can anyone read a JWT payload?+
Yes. A signed JWT is encoded, not encrypted. base64url is a reversible text encoding with no key, so anyone who sees the token can read every claim in it. Never put passwords, API keys, or personal data you would not show to every holder of the token into a JWT payload. If the claims must stay private, the token has to be a JWE, which is encrypted.
What do exp, iat, and nbf mean?+
They are NumericDates: whole or fractional seconds since 1970-01-01 00:00:00 UTC, not milliseconds. exp is the moment after which the token must be rejected, nbf the moment before which it must be rejected, and iat the moment it was issued. For example, exp 1767225600 is 2026-01-01 00:00:00 UTC. Many verifiers allow a little clock skew, typically between zero and five minutes. A 13-digit value is almost always a millisecond timestamp written by mistake, and this page flags it.
What is the difference between HS256 and RS256?+
HS256 is HMAC with SHA-256. One shared secret both signs and verifies, so every service that can check a token can also create one. RS256 is an RSA signature with SHA-256. The issuer signs with a private key and anyone verifies with the public key, which providers usually publish as a JWK set. HS256 suits a single system that issues and checks its own tokens; RS256, ES256, or EdDSA suit tokens that cross a trust boundary, such as one identity provider and many APIs.
Why is alg none dangerous?+
alg none marks an unsecured JWT: the signature segment is empty, so anyone can write any claims they like. The specification allows such tokens, but a verifier that accepts them, or that lets the token's own header decide which algorithm to use, can be handed a forged token. Configure your JWT library with the exact algorithms you expect and reject everything else, including none.
How do I verify a JWT signature?+
Recompute or check it over the first two segments exactly as they appear in the token (header, a dot, then payload) using the right key. For HS256 that key is the shared secret; for RS256, PS256, ES256, or EdDSA it is the issuer's public key, usually found at the jwks_uri listed in the provider's /.well-known/openid-configuration document. Paste either into the verifier above. A real verifier then checks exp, nbf, iss, and aud as well, because a valid signature only proves who made the token, not that it is still acceptable.
Should I use a JWT or a session cookie?+
A classic session cookie holds a random ID that the server looks up in its own store, so signing out or revoking access takes effect immediately. A JWT carries its claims with it, so any service holding the key can check it without a lookup, but it stays valid until exp even after the user signs out unless you add a denylist. Many sites use short-lived JWTs between services and a server-side session for the browser. The two are not exclusive: a JWT can itself be stored in a cookie.
What is a JWE?+
A JSON Web Encryption token (RFC 7516) is encrypted rather than only signed. Its compact form has five segments: protected header, encrypted key, initialization vector, ciphertext, and authentication tag. Only the header is readable; the claims are inside the ciphertext and need the recipient's private key or shared key to decrypt. This page recognises a JWE, shows its header, and says plainly that the claims cannot be read without the key.