What is a JSON Web Token (JWT) and how it is structured
A JSON Web Token (JWT), standardized under IETF RFC 7519, is a compact, URL-safe container format for asserting claims between two parties. JWTs are the dominant standard in OAuth 2.0 and OpenID Connect (OIDC) authentication architectures.
A token consists of three Base64URL-encoded JSON segments joined by periods: the Header (declaring algorithm type like HMAC SHA256 or RSA), the Payload (containing entity claims and permission scopes), and the Cryptographic Signature (verifying integrity).
How to decode a JWT token online
- Paste your JWT bearer token. Copy the encoded token string (format: header.payload.signature) from your authorization header, OAuth2 response, or session cookie and paste it above.
- Click Decode Token Claims. The browser splits the three dot-separated parts and runs Base64URL decoding in local memory.
- Inspect header parameters and registered claims. View cryptographic algorithms (e.g. RS256, HS256), Key ID (kid), subject (sub), issuer (iss), audience (aud), and human-readable expiration timestamps.
- Export decoded JSON or CSV. Copy formatted claims JSON directly or download a structured CSV table for authentication auditing and debugging.
What data the JWT extractor extracts
- Decoded Header: Algorithm (
alg), Token Type (typ), Key ID (kid), and X.509 Thumbprints. - Standard Registered Claims: Subject (
sub), Issuer (iss), Audience (aud), and JWT ID (jti). - Time Claims Converted to Human Dates: Expiration Time (
exp), Issued At (iat), and Not Before (nbf). - Custom Application Claims: User roles, email addresses, tenant IDs, and feature flags.
- Formatted JSON & CSV Exports: Clean copy-pasteable JSON objects and tabular parameter sheets.
Supported token formats and algorithms
- Specifications: RFC 7519 (JWT), RFC 7515 (JWS), RFC 7517 (JWK), and OpenID Connect Core 1.0.
- Supported Algorithms: RS256, RS384, RS512, HS256, HS384, HS512, ES256, ES384, ES512, PS256, and EdDSA.
- Token Types: Standard Bearer Tokens, ID Tokens, Access Tokens, and Refresh Tokens.
Why online JWT decoders pose serious security risks
Pasting live JWT tokens into server-side online decoders transmits live user sessions, private API keys, and corporate tenant IDs to external web servers. If an unauthorized party intercepts or logs an unexpired JWT, they can impersonate the user without needing their password.
EasyExtract executes all Base64URL decoding locally inside your browser's JavaScript engine using window.atob and Unicode text decoders. Your tokens, secret claims, and session keys are never transmitted across any network.
What this tool does not do
- It does not verify cryptographic signatures; verifying signatures requires supplying private signing keys or public JWKS endpoints.
- It does not decrypt JWE (JSON Web Encryption) encrypted payloads without the decryption key.
Common reasons developers decode JWTs
- OAuth2 & OIDC Debugging: Verifying that authorization servers issue tokens with correct scopes and audience claims.
- Inspecting Token Expiration: Checking exact expiration timestamps to troubleshoot premature token refresh loops.
- API Security Auditing: Ensuring private server secrets are not inadvertently exposed inside unencrypted token payloads.
JWT decoding compared with certificate and Base64 tools
If you need to decode a raw Base64 string rather than a 3-part JWT, use the Base64 decoder. For inspecting SSL/TLS certificates and public keys, use the certificate extractor.
For a complete technical walkthrough of token anatomy and claim structures, read our master guide on how to decode JWT tokens in your browser.
Frequently asked questions
Can I decode a JWT token online without a secret key?
Yes. The header and payload of a standard JWT are Base64URL-encoded, not encrypted. Anyone can decode and inspect claims without a secret key. A secret key is only needed to verify or generate the cryptographic signature.
Is it safe to decode JWT tokens online?
It is only safe if the tool runs 100% in your browser. EasyExtract decodes tokens locally using JavaScript; no token data is ever uploaded or logged.
What does the 'exp' claim mean in a JWT?
The 'exp' (expiration time) claim is a Unix timestamp indicating when the token ceases to be valid. EasyExtract automatically converts this timestamp into a human-readable UTC and local date.
What are the three parts of a JWT?
A JWT consists of three parts separated by dots (.): Header (algorithm and token type), Payload (user claims and scopes), and Signature (cryptographic hash).
What is the difference between JWT and JWE?
A JWT is signed but readable (Base64URL encoded). A JWE (JSON Web Encryption) encrypts the payload so that its contents cannot be read without a private decryption key.
Can I decode expired JWT tokens?
Yes. An expired token's claims remain completely readable. EasyExtract will display the claims and flag the expiration date.
How do I extract claims from a JWT into CSV?
Paste your token, click Decode Token Claims, and click Download Claims CSV to export all keys, standard names, and values into a spreadsheet-ready format.