BasicApps Logo
JWT Parser

Parse, decode, and validate JSON Web Tokens (JWT) with header, payload, and signature analysis

JWT Token Parser

Characters: 0

Symmetric Algorithms

HS256: HMAC SHA-256 (most common)
HS384: HMAC SHA-384
HS512: HMAC SHA-512
Use case: Single application systems
Security: Shared secret required

Asymmetric Algorithms

RS256: RSA SHA-256
ES256: ECDSA SHA-256
PS256: RSA-PSS SHA-256
Use case: Distributed systems
Security: Public/private key pairs

Example JWT Tokens

A JWT is three Base64URL-encoded segments joined by dots. The first is the header — it tells you the algorithm (HS256, RS256, ES256, etc.) and token type. The second is the payload — where the actual claims live: sub (who this token is for), exp (expiry timestamp), iat (issued at), plus any custom claims your auth system adds. The third is the signature. This tool decodes the first two and shows them as readable JSON. It cannot verify the signature without the signing key, so treat the decoded payload as informational only — it doesn't tell you whether the token is valid, only what it claims to contain.

The expiry timestamp trips people up regularly

The exp claim is a Unix timestamp in seconds, not milliseconds. So a value like 1753660800 means a specific date — not "this many milliseconds from now." If you paste a token here and the expiry time looks wildly wrong, that's usually why: the issuing system accidentally used milliseconds instead of seconds, which puts the expiry somewhere in the year 2525. Worth checking in the payload view. Also, the nbf (not before) claim is less commonly used but works the opposite way — the token is not valid until that timestamp. You'll see it in tokens that are issued ahead of time and should only become active later. The parsed payload view here shows all claims including these, with the timestamps converted to human-readable date strings so you don't have to do the conversion manually.