← All guides

What is a JWT and how do you read one?

· 2 min read

A JWT (JSON Web Token) is a small piece of text most often used to prove that a user has signed in. It has three parts separated by dots, and reading it is easier than it looks.

Three parts: header, payload, signature

A JWT looks like this: xxxxx.yyyyy.zzzzz. Each of the three parts separated by dots is encoded with Base64url.

A JWT is not encrypted

This is the most common misunderstanding. A standard JWT is signed but not encrypted. The payload is only encoded, so anyone who decodes Base64url can read it. Never put passwords, card numbers or other secrets in a JWT.

The signature only guarantees that the token has not been changed since it was issued. It does not hide the contents.

Reading is not the same as verifying

Tools like the JWT decoder only read the payload. Verifying the signature needs the secret (or public) key and should be done by the server that accepts the token. Seeing the contents of a token does not prove it is genuine, since anyone can craft a JWT with fake contents.

Time fields: exp, iat, nbf

These fields hold the number of seconds since 1 January 1970 (Unix time). exp is the expiry time, iat is when it was issued and nbf means "not valid before". To check whether a token is still valid, see whether exp is after the current time. The timestamp tool turns the numbers into readable dates.

Common security mistakes

Do not share valid tokens from live systems with others or on public sites. Our tool decodes the token in your browser and never sends it to a server.

More guides