Anatomy of a JWT
A JWT is three base64url segments separated by dots: header.payload.signature. The header declares the algorithm (alg) and type; the payload carries claims like sub (subject), iat (issued at), and exp (expiry); iat and exp are Unix timestamps. The signature proves the token wasn't tampered with.
Reading the decode
- Expiry countdown — the tool converts
expto "expires in Xh Ym" or "expired X ago". A token with noexpnever expires — a security smell in most systems. - Signature check — the decoder verifies the token has three segments and that the signature is valid base64url; it does not cryptographically verify the signature (that needs the secret key, which you should never paste anywhere).
- alg=none — if the header says
alg: "none", the token isn't actually signed — classic attack vector; your server should reject it.
Security note
JWTs are base64, not encrypted — anyone can read the payload. Never put secrets in them, and never paste tokens containing sensitive claims into online tools. This one runs entirely in your browser.