1. Anatomy of a JSON Web Token (RFC 7519)
A JSON Web Token (JWT), defined in RFC 7519, is an open, industry-standard method for securely representing claims between two parties in modern microservices, OAuth2, and OpenID Connect (OIDC) architectures.
A compact JWT consists of three distinct parts separated by dots (.):
<HEADER>.<PAYLOAD>.<SIGNATURE>
Specifies the token type ("typ": "JWT") and the cryptographic signing algorithm used, such as HMAC SHA256 (HS256) or RSA (RS256).
Contains the actual statements about the entity (user, service account, or machine) and metadata such as issuer (iss), audience (aud), and expiration (exp).
A cryptographic hash created by hashing the encoded header and payload with a private key or secret, proving authenticity and preventing tampering.
2. Standard Registered JWT Claims Every Engineer Must Know
While payloads can contain custom application data, RFC 7519 defines standard registered claims:
iss(Issuer): The identity provider that issued the token (e.g.,https://accounts.google.comorhttps://cognito-idp.us-east-1.amazonaws.com/...).sub(Subject): The unique subject identifier (user ID or service account ID).aud(Audience): The intended recipient or backend API service.exp(Expiration Time): A Unix epoch timestamp (seconds since Jan 01 1970) indicating when the token expires.nbf(Not Before): Unix timestamp before which the token must not be accepted.iat(Issued At): Unix timestamp when the token was created.jti(JWT ID): A unique non-reusable token identifier to prevent replay attacks.
Our free tool automatically extracts the exp claim, translates the Unix timestamp into a readable UTC date string, and verifies whether the token is currently ACTIVE or EXPIRED relative to your local clock.
3. How to Use the Free Online JWT Decoder
- Open the Free JWT Decoder.
- Paste your compact JWT token (with or without the
Bearerprefix). - Click Decode.
- The tool splits the token, decodes the Base64URL-encoded header and payload, and displays both formatted JSON objects alongside the token's expiration status.
4. Command-Line JWT Inspection with jq & Bash
In terminal sessions where you cannot use a browser, inspect JWTs using this clean bash/jq pipeline:
# Decode JWT Payload using bash and jq (no npm or external packages)
decode_jwt() {
echo "$1" | cut -d. -f2 | base64 -d 2>/dev/null | jq .
}
# Example usage:
decode_jwt "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTYiLCJuYW1lIjoiTmF2ZWVkIiwiZXhwIjoxNzkxMzUyMTM5fQ.abc..."
# Inspect token expiry human-readable date
date -r $(echo "$TOKEN" | cut -d. -f2 | base64 -d 2>/dev/null | jq -r .exp) -u
5. Common JWT Security Vulnerabilities in Cloud Architectures
- The "alg: none" Exploit: Vulnerable backends accept tokens whose header sets
"alg": "none", bypassing signature verification entirely. - Symmetric vs. Asymmetric Confusion: Attacking APIs that expect RS256 by sending HS256 signed with the public RSA key as a shared HMAC secret.
- Excessive Expiration Lifetimes: Issuing access tokens with 30-day lifespans instead of short-lived (15-minute) tokens backed by secure refresh tokens.
Frequently Asked Questions
Yes, 100% free with unlimited token debugging.
Yes! Unlike popular third-party token decoders that transmit tokens to cloud backends, our tool parses tokens 100% client-side in your local browser sandbox. No tokens are sent over the network.
No, and for good reason: verifying a signature requires uploading your private key or HMAC secret to the browser. Client-side decoding inspects claims and headers safely without exposing sensitive server signing secrets.
Our tool compares the 'exp' claim against the current timestamp and highlights the expiration date in orange with a warning banner.
This tool is an inspector and debugger designed for safe inspection. Re-signing requires access to private keys which should never be handled in a web browser.