What's inside a JWT
A JSON Web Token has three parts separated by dots:
- Header: the token type and signing algorithm, such as
{"alg":"HS256","typ":"JWT"}. - Payload: the claims, such as the user ID (
sub), roles and expiry time (exp). - Signature: a hash of the header and payload made with a secret or private key.
The header and payload are Base64URL-encoded JSON, which is why this tool can decode them without any key.
Common registered claims
| Claim | Meaning |
|---|---|
iss | Issuer: who created the token |
sub | Subject: usually the user ID |
aud | Audience: who the token is meant for |
exp | Expiration time (Unix timestamp) |
nbf | Not valid before (Unix timestamp) |
iat | Issued at (Unix timestamp) |
jti | Unique token ID |
Need to read a timestamp on its own? Use the Unix timestamp converter.