What a JWT is

A JSON Web Token (JWT) is a compact string used to pass identity or permission data between a client and a server. It has three parts separated by dots: header.payload.signature. Each part is Base64URL encoded.

What is inside

  • Header: the token type and signing algorithm, such as HS256 or RS256.
  • Payload: the claims, such as who the user is and when the token expires.
  • Signature: proof the token was issued by someone holding the key and was not altered.

Common claims

  • iss (issuer) and aud (audience): who issued the token and who it is for.
  • sub (subject): usually the user ID.
  • exp (expiry): a Unix timestamp in seconds after which the token must be rejected.
  • nbf (not before) and iat (issued at): timing claims.
  • jti: a unique token ID.

Decode a token with Serpgy

  1. Open the JWT Decoder.
  2. Paste the token.
  3. Read the header and payload as formatted JSON.
  4. Check the expiry to see whether the token is still valid.
  5. Clear the field when you are finished.

Decoding is not verifying

Anyone can decode a JWT, because the header and payload are only encoded, not encrypted. Decoding shows what a token says, not whether it is genuine. Your server must verify the signature with the correct key and check expiry, issuer and audience before trusting it.

Security tips

  • Never put passwords or other secrets in the payload.
  • Treat a token like a password. Anyone who holds a valid one can act as that user until it expires.
  • Prefer short expiry times and refresh tokens.
  • Reject tokens that use the none algorithm or an unexpected algorithm.
  • Avoid pasting live production tokens into tools you do not trust. Serpgy decodes locally in your browser.