Developer

What Is a JWT? Header, Payload and Signature Explained

ToolOrbit Engineering 2 min readUpdated
What Is a JWT? Header, Payload and Signature Explained

JSON Web Tokens (JWTs) are everywhere in modern authentication, from OAuth flows to API keys. When something goes wrong, you often just need to see what is inside the token. The ToolOrbit JWT Decoder splits a token into its parts and shows you the header and payload in readable JSON, entirely within your browser.

The three parts of a JWT

A JWT is three Base64URL-encoded sections joined by dots: the header, the payload, and the signature. The header describes the signing algorithm, the payload carries the claims, and the signature lets a server confirm the token has not been tampered with.

header.payload.signature

eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjMiLCJleHAiOjE3...}.SflKxw...

Reading the claims

  • sub: the subject, usually the user or account the token represents
  • exp: expiry as a Unix timestamp; the token is invalid after this moment
  • iat: issued-at time, useful for spotting clock skew or stale tokens
  • iss and aud: the issuer and intended audience, which a verifier should check
  • Custom claims: roles, scopes, tenant IDs, and other app-specific data

The decoder highlights the expiry so you can immediately tell whether a token is still valid, which is one of the most common debugging questions.

Warning: Decoding only reads the token; it does not verify the signature. Never trust a JWT's contents in your backend without verifying the signature with the correct key.

Using the JWT Decoder safely

Paste a token to see its header and payload instantly. Because decoding happens locally and the payload of a JWT is not encrypted, anyone holding the token can read it. Treat tokens like passwords: do not paste production tokens into untrusted online tools. ToolOrbit keeps everything in your browser, but the habit matters everywhere.

Best practices

Keep payloads small and avoid putting sensitive personal data in claims, since they are merely encoded, not hidden. Set short expiries, validate iss and aud on the server, and remember that the only thing standing between a forged token and your API is a proper signature check.

Decoding is not verifying

The three segments of a JWT are only Base64url-encoded JSON — anyone can decode them, and the signature check is what makes a token trustworthy. A decoder that shows you the payload is doing data inspection, not security validation. To actually accept a token you validate the signature against the issuer’s keys, check exp and nbf, and confirm the audience. Troubleshoot with the decoder; never build trust decisions on a decoded-but-unverified token.

Claims worth knowing
ClaimMeaningCheck it with
expExpiry time (seconds since epoch)Compare to now
iatIssued atSpot age
nbfNot valid beforeCompare to now
iss / audIssuer / audienceMatch against your config

Tools mentioned

More reading

View all guides
What Is Base64? How Encoding Works and Common Mistakes
Developer

What Is Base64? How Encoding Works and Common Mistakes

What Base64 encoding actually does, where it is used, and the mistakes that cause broken or oversized output.

2 min readUpdated
encodeURI vs encodeURIComponent: Which One to Use
Developer

encodeURI vs encodeURIComponent: Which One to Use

How percent-encoding works, the difference between encoding a whole URL and a single component, and the mistakes that break links.

2 min readUpdated
What Is a UUID? Version 4 vs Version 7 Explained
Developer

What Is a UUID? Version 4 vs Version 7 Explained

What a UUID looks like, why version 4 is the safe default, when version 7 is better, and best practices for IDs.

2 min readUpdated
How SHA-256 and SHA-512 Hashes Work: Hashing vs Encryption
Developer

How SHA-256 and SHA-512 Hashes Work: Hashing vs Encryption

What a hash function does, how to choose between SHA-256 and SHA-512, and why hashing is not encryption.

2 min readUpdated
What Is HTML Encoding? Entities & Escaping Explained
Developer

What Is HTML Encoding? Entities & Escaping Explained

Learn how HTML encoding works, why escaping prevents XSS and layout breaks, and how to encode and decode named, decimal, and hex entities.

2 min readUpdated
Unix Time Explained: Seconds, Milliseconds and Time Zones
Developer

Unix Time Explained: Seconds, Milliseconds and Time Zones

What a Unix timestamp is, how to tell seconds from milliseconds, how time zones come into it, and the values worth recognising.

2 min readUpdated
Binary, Octal, Decimal and Hex: How Number Bases Work
Developer

Binary, Octal, Decimal and Hex: How Number Bases Work

How positional number bases work, why very large values need exact arithmetic, and the hex and binary values you meet every day.

2 min readUpdated
Regex Basics: How Patterns, Flags and Character Classes Work
Developer

Regex Basics: How Patterns, Flags and Character Classes Work

How a regular expression is built, what the flags change, and the character classes you will use most.

2 min readUpdated