What a JWT is
A JSON Web Token (JWT) is a compact string used to pass identity or permission data between a client and a server. It has three parts separated by dots: header.payload.signature. Each part is Base64URL encoded.
What is inside
- Header: the token type and signing algorithm, such as HS256 or RS256.
- Payload: the claims, such as who the user is and when the token expires.
- Signature: proof the token was issued by someone holding the key and was not altered.
Common claims
- iss (issuer) and aud (audience): who issued the token and who it is for.
- sub (subject): usually the user ID.
- exp (expiry): a Unix timestamp in seconds after which the token must be rejected.
- nbf (not before) and iat (issued at): timing claims.
- jti: a unique token ID.
Decode a token with Serpgy
- Open the JWT Decoder.
- Paste the token.
- Read the header and payload as formatted JSON.
- Check the expiry to see whether the token is still valid.
- Clear the field when you are finished.
Decoding is not verifying
Anyone can decode a JWT, because the header and payload are only encoded, not encrypted. Decoding shows what a token says, not whether it is genuine. Your server must verify the signature with the correct key and check expiry, issuer and audience before trusting it.
Security tips
- Never put passwords or other secrets in the payload.
- Treat a token like a password. Anyone who holds a valid one can act as that user until it expires.
- Prefer short expiry times and refresh tokens.
- Reject tokens that use the none algorithm or an unexpected algorithm.
- Avoid pasting live production tokens into tools you do not trust. Serpgy decodes locally in your browser.