Developer

How to Decode and Inspect JSON Web Tokens (JWT): Header, Payload, and Signature Explained

Understand the structure of JSON Web Tokens without security risks. Learn how Base64url encoding works, how to inspect claims locally, and how to verify cryptographic signatures.

The Synctoolo Team··10 min read
Binary data and token authentication streams on a monitor

If you build modern web applications, REST APIs, or microservices, you work with JSON Web Tokens (JWT) every single day. They power user sessions in Next.js, carry OAuth2 permissions from Google and GitHub, and authenticate requests across cloud architectures.

Yet when developers need to inspect a token to check permissions, user IDs, or expiration timestamps, they frequently paste production tokens into public online web debuggers. If that token contains customer email addresses or private claims, pasting it into a third-party server creates an immediate security and compliance violation.

This guide explains how JWTs are structured at the bitwise level, why they use Base64url encoding, how to decode them locally in your browser, and how to format the extracted JSON payloads using Synctoolo's Base64 Encoder / Decoder and JSON Formatter.

The Anatomy of a JWT: Three Parts Separated by Dots

A JSON Web Token is a compact, URL-safe string composed of three distinct sections separated by periods (.):

header.payload.signature

Each section serves a specific cryptographic function:

1. The Header: Algorithm and Token Type

The header typically contains two fields: the signing algorithm being used (such as HS256 or RS256) and the token type (JWT):

{
  "alg": "HS256",
  "typ": "JWT"
}

2. The Payload: Claims and User Identity

The payload stores the actual claims: statements about an entity (typically the user) and metadata. Standard registered claims defined by RFC 7519 include:

  • sub (Subject): The unique identifier of the user.
  • iat (Issued At): Unix epoch timestamp when the token was created.
  • exp (Expiration Time): Unix epoch timestamp after which the token is invalid.
  • iss (Issuer): The identity provider that generated the token.

3. The Signature: Cryptographic Integrity

The signature ensures that the token has not been tampered with in transit. It is generated by taking the encoded header, the encoded payload, a secret key, and hashing them with the specified algorithm:

HMACSHA256(
  base64UrlEncode(header) + "." + base64UrlEncode(payload),
  secret
)
Server network cables and datacenter infrastructure
Inspecting token claims locally prevents exposing sensitive bearer tokens across public servers. Photo by Jordan Harrison on Unsplash.

Why JWTs Use Base64url Instead of Standard Base64

Standard Base64 contains the plus symbol (+) and forward slash (/). In HTTP Authorization headers and URL query strings, these characters cause parsing conflicts:

  • + is frequently interpreted by web servers as a space.
  • / is interpreted by routers as a path separator.
  • = padding characters interfere with query parameter syntax.
Feature Standard Base64 (RFC 4648 §4) Base64url (RFC 4648 §5)
Character 62 + (Plus) - (Minus / Hyphen)
Character 63 / (Slash) _ (Underscore)
Padding Character = (Equal sign, 0-2 chars) Omitted entirely
URL and Query Safe No (Requires URL encoding) Yes (Safe in headers and URLs)

How to Decode a JWT in 1 Line of Client-Side JavaScript

Because the header and payload are simply Base64url-encoded JSON strings (NOT encrypted), you can decode any JWT in pure JavaScript without external libraries:

function parseJwtPayload(token) {
  const base64Url = token.split('.')[1];
  const base64 = base64Url.replace(/-/g, '+').replace(/_/g, '/');
  const jsonPayload = decodeURIComponent(
    atob(base64)
      .split('')
      .map(c => '%' + ('00' + c.charCodeAt(0).toString(16)).slice(-2))
      .join('')
  );
  return JSON.parse(jsonPayload);
}

Need to inspect and format an encoded token right now? Paste the middle section into our client-side Base64 Decoder and format the resulting object with our JSON Formatter. Your token executes 100% in local browser memory with zero network transmission.

Tools mentioned in this article

FAQ

Is a JSON Web Token encrypted by default?+

No. Standard JWTs are signed and Base64url encoded, but not encrypted. Anyone who intercepts the token can read the header and payload in plain text. Never store unencrypted passwords or API secrets inside JWT claims.

Why does JWT use Base64url instead of standard Base64?+

Standard Base64 contains '+' and '/' characters, which have special meanings in URLs and HTTP query parameters. Base64url replaces them with '-' and '_' and omits '=' padding, making tokens safe for URL transmission.

Can an expired JWT still be decoded?+

Yes. Token expiration (the 'exp' claim) only affects whether your authentication backend accepts the token. The Base64url encoding remains fully readable regardless of whether the token has expired.

Is it safe to paste JWT tokens into online debuggers?+

Pasting production JWTs containing private customer information or session credentials into server-based debuggers exposes your data to remote logging. Synctoolo provides client-side Base64 and JSON formatting tools that process data entirely in local memory.

S
The Synctoolo Team

We build and review free, privacy-first tools at Synctoolo.

Keep reading