Free Tools
Blog

What's Inside a JWT? How to Decode One Safely

By Admin Editor · September 18, 2026

A JSON Web Token (JWT) looks like a random string, but it's actually three readable parts glued together — once you know how to split it apart.

What a JWT is made of

A JWT is three Base64URL-encoded sections separated by dots: header.payload.signature. The header describes the token type and signing algorithm. The payload contains the actual claims — data like a user ID, an expiration time, or custom fields the issuing server chose to include. The signature is a cryptographic value that lets the server verify the token hasn't been tampered with, but it can't be "decoded" back into readable data the way the header and payload can.

Why the payload is readable, not secret

Because the header and payload are just Base64-encoded JSON — not encrypted — anyone who has the token can decode and read its contents, including the token's owner. JWTs aren't designed to hide data from the person holding them; they're designed so a server can trust the data wasn't modified, using the signature. Never put a password or other genuinely secret value inside a JWT's payload.

How to decode a JWT

Paste a token into the JWT Decoder to instantly see its decoded header and payload as readable JSON. Note that this only decodes the token — it does not verify the signature, so a decoded payload isn't proof the token is authentic or hasn't expired.

A common payload you'll see

{
  "sub": "1234567890",
  "name": "Jane Doe",
  "exp": 1732492800
}

sub (subject) identifies who the token is about, and exp (expiration) is a Unix timestamp marking when the token stops being valid — see our Unix Timestamp guide if you need to convert that into a readable date.

FAQ

Is decoding a JWT the same as verifying it? No. Decoding just reads the header and payload; verifying checks the signature against a secret or public key to confirm the token is authentic and untampered. Verification requires the signing key and should always happen server-side.

Can I edit a JWT's payload after decoding it? You can construct a modified token with different data, but without the original signing key you can't produce a valid signature for it — a server that properly verifies signatures will reject the tampered token.

Why does the same JWT decode differently in different tools? It shouldn't, for the header and payload — they're standard Base64URL-encoded JSON. If you see different output, double check you copied the entire token, including all three dot-separated parts.

Decode a JWT now

Try the free JWT Decoder — decoding happens entirely in your browser. See more developer tools.

Related reading

JWTs are Base64URL-encoded under the hood — see What Is Base64 Encoding and When Should You Use It? for the underlying format. Browse the full blog for more guides.