JWT Decoder
Decode JWT (JSON Web Token) header, payload, and signature to inspect claims.
π How to Use
Paste the JWT token you want to decode. e.g. eyJhbGciOiJIUzI1NiIs...
Click π Decode to split and display the header, payload, and signature.
Use π Copy buttons to save the header or payload to clipboard.
About the JWT Decoder
A JSON Web Token (JWT, RFC 7519) is a compact, URL-safe string used to assert claims between two parties, most commonly as a bearer credential after a user signs in to a web or mobile application. A JWT encodes a small JSON object that the server can read to identify a user, their roles, and an expiration, without a database lookup on every request. This decoder lets you inspect the contents of a token — its header, payload, and signature — entirely in your browser, which is exactly what you need when debugging authentication failures.
How it works
A JWT has three base64url-encoded parts joined by dots: header.payload.signature. The header declares the token type (typ) and the signing algorithm (alg, for example HS256 or RS256). The payload carries the claims — standard ones like sub (subject), exp (expiration), iat (issued-at), iss (issuer), and aud (audience), plus any custom claims. The signature is computed by the issuer over the base64url of the header and payload using the algorithm from the header and a secret (HMAC) or private key (RSA/ECDSA).
Base64url is the variant this tool must handle: it replaces + with - and / with _, and omits the = padding, so the token is safe inside URLs and headers. Decoding is just reversing that and parsing JSON — it is reading, not security. The critical distinction: decoding reveals the payload to anyone who has the token (a JWT is signed, not encrypted); only signature verification against the secret or public key proves the token was not tampered with. This tool decodes and reads only — it does not verify signatures, so never trust claims from an unverified token.
Common use cases
- Inspecting a token returned by an OAuth2 or OpenID Connect server
- Debugging an expired
expor wrongaudcausing 401 responses - Auditing which claims and scopes an identity provider actually issued
- Verifying the
algheader before implementing server-side verification - Teaching how the three-part structure maps to header, payload, and signature
Worked example
Given this (unsigned, sample) token:
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkFkYSBMb3ZlbGFjZSIsImlhdCI6MTczNTY4OTYwMCwiZXhwIjoxNzM1Nzc2MDAwfQ.sOmE_s1gN0tBp2xV7l3oFakeSig
Decoding the first segment yields the header:
{ "alg": "HS256", "typ": "JWT" }
And the second segment yields the payload:
{
"sub": "1234567890",
"name": "Ada Lovelace",
"iat": 1735689600,
"exp": 1735776000
}
Anyone can reproduce this output from the token — that is why a JWT must never contain secrets, and why you must verify the signature before acting on the claims.
Frequently asked questions
Does decoding a JWT verify its signature?
No. Decoding only base64url-decodes the header and payload so you can read the claims. Proving authenticity requires signature verification against the secret or public key, which this tool does not perform. Never trust claims from an unverified token.
Is the JWT payload encrypted?
No. A standard JWT payload is base64url-encoded, not encrypted, so anyone who has the token can read it. Sensitive data must never be placed in a JWT payload unless you use a separate JSON Web Encryption (JWE) token.
What are the common payload claims?
Standard registered claims include sub (subject), iss (issuer), aud (audience), exp (expiration time), iat (issued-at time), and nbf (not-before time). Custom application-specific claims can also appear alongside them.
Why does my token fail to decode?
The most common causes are a truncated token, a missing third (signature) segment, copy-paste whitespace, or a JWE token that is encrypted rather than merely signed. The tool expects exactly three base64url parts separated by dots.
Is my token sent to a server?
No. All decoding runs locally in your browser, so live access tokens and credentials never leave your device. This makes the tool safe for inspecting real authentication tokens.
JWT λμ½λλ?
JSON Web Token(JWT, RFC 7519)μ λ 주체 κ°μ ν΄λ μμ μ λ¬νκΈ° μν΄ μ¬μ©νλ κ°κ²°νκ³ URLμ μμ ν λ¬Έμμ΄λ‘, μ£Όλ‘ μ¬μ©μκ° μΉμ΄λ λͺ¨λ°μΌ μ ν리μΌμ΄μ μ λ‘κ·ΈμΈν λ€ μ λ¬νλ λ² μ΄λ¬ μ격μ¦λͺ μΌλ‘ μ°μ λλ€. JWTλ μμ JSON κ°μ²΄λ₯Ό μΈμ½λ©νμ¬ μλ²κ° λ§€ μμ²λ§λ€ λ°μ΄ν°λ² μ΄μ€λ₯Ό μ‘°ννμ§ μκ³ λ μ¬μ©μμ μν , λ§λ£ μκ°μ μλ³ν μ μκ² ν΄ μ€λλ€. μ΄ λμ½λλ ν ν°μ λ΄μ© — ν€λ, νμ΄λ‘λ, μλͺ — μ μ μ μΌλ‘ λΈλΌμ°μ μμμ κ²μ¬ν μ μκ² ν΄ μ£Όλ©°, μΈμ¦ μ€ν¨λ₯Ό λλ²κΉ νκ±°λ μλ²κ° μ€μ λ‘ λ°κΈν λ΄μ©μ κ°μ¬ν λ νμν λꡬμ λλ€.
μλ λ°©μ
JWTλ base64urlλ‘ μΈμ½λ©λ μΈ λΆλΆμ μ μΌλ‘ μ΄μ΄ λΆμΈ header.payload.signature ννμ
λλ€. ν€λλ ν ν° μ ν(typ)κ³Ό μλͺ
μκ³ λ¦¬μ¦(alg, μ: HS256, RS256)μ μ μΈν©λλ€. νμ΄λ‘λλ ν΄λ μμ λ΄μ΅λλ€ — sub(μ λͺ©), exp(λ§λ£), iat(λ°κΈ μκ°), iss(λ°κΈμ), aud(μμ μ) κ°μ νμ€ ν΄λ μκ³Ό μμμ 컀μ€ν
ν΄λ μμ
λλ€. μλͺ
μ λ°κΈμκ° ν€λμ νμ΄λ‘λμ base64urlμ λν΄ ν€λμ λͺ
μλ μκ³ λ¦¬μ¦κ³Ό λΉλ°ν€(HMAC) λλ κ°μΈν€(RSA/ECDSA)λ‘ κ³μ°ν©λλ€.
Base64urlμ μ΄ λκ΅¬κ° λ°λμ λ€λ€μΌ νλ λ³νμ
λλ€. + λμ -λ₯Ό, / λμ _λ₯Ό μ°κ³ = ν¨λ©μ μλ΅νμ¬ ν ν°μ΄ URLκ³Ό ν€λμ λ€μ΄κ°λ μμ ν©λλ€. λμ½λ©μ μ΄λ₯Ό μμΌλ‘ λλλ¦¬κ³ JSONμ νμ±νλ κ²μΌ λΏ, μ½κΈ°μ΄μ§ 보μμ΄ μλλλ€. ν΅μ¬μ μΈ κ΅¬λΆ: λμ½λ©μ ν ν°μ κ°μ§ λꡬλ νμ΄λ‘λλ₯Ό λ³Ό μ μκ² ν©λλ€(JWTλ μνΈνκ° μλλΌ μλͺ
λ κ°μ
λλ€). μλͺ
κ²μ¦λ§μ΄ λΉλ°ν€ λλ 곡κ°ν€λ‘ ν ν°μ΄ λ³μ‘°λμ§ μμκ³ μ§μ§ λ°κΈμμκ²μ μμμ μ¦λͺ
ν©λλ€. μ΄ λꡬλ λμ½λ©/μ½κΈ°λ§ νκ³ μλͺ
μ κ²μ¦νμ§ μμΌλ―λ‘, κ²μ¦λμ§ μμ ν ν°μ ν΄λ μμ μ λ μ λ’°νμ§ λ§μΈμ.
μμ£Ό μ°λ κ²½μ°
- OAuth2 λλ OpenID Connect μλ²κ° λ°νν ν ν° κ²μ¬
- λ§λ£λ
expλλ μλͺ»λaudλ‘ μΈν 401 μλ΅ λλ²κΉ - ID 곡κΈμκ° μ€μ λ‘ λ°κΈν ν΄λ μκ³Ό μ€μ½ν κ°μ¬
- μλ² μΈ‘ κ²μ¦μ ꡬννκΈ° μ
algν€λ νμΈ - μΈ λΆλΆ κ΅¬μ‘°κ° ν€λ, νμ΄λ‘λ, μλͺ μ μ΄λ»κ² λμλλμ§ νμ΅
μ¬μ© μ
λ€μ (μλͺ λμ§ μμ μμ) ν ν°μ΄ μ£Όμ΄μ§λ©΄:
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkFkYSBMb3ZlbGFjZSIsImlhdCI6MTczNTY4OTYwMCwiZXhwIjoxNzM1Nzc2MDAwfQ.sOmE_s1gN0tBp2xV7l3oFakeSig
첫 λ²μ§Έ μΈκ·Έλ¨ΌνΈλ₯Ό λμ½λ©νλ©΄ ν€λκ° λμ΅λλ€:
{ "alg": "HS256", "typ": "JWT" }
λ λ²μ§Έ μΈκ·Έλ¨ΌνΈλ νμ΄λ‘λλ₯Ό λ°νν©λλ€:
{
"sub": "1234567890",
"name": "Ada Lovelace",
"iat": 1735689600,
"exp": 1735776000
}
λꡬλ ν ν°μμ μ΄ μΆλ ₯μ μ¬νν μ μμ΅λλ€ — κ·Έλμ JWTμ λΉλ°μ λ΄μΌλ©΄ μ λλ©°, ν΄λ μμ μμ‘΄ν΄ νλνκΈ° μ μ λ°λμ μλͺ μ κ²μ¦ν΄μΌ ν©λλ€.
μμ£Ό 묻λ μ§λ¬Έ
JWTλ₯Ό λμ½λ©νλ©΄ μλͺ μ΄ κ²μ¦λλμ?
μλλλ€. λμ½λ©μ ν€λμ νμ΄λ‘λλ₯Ό base64url λμ½λ©νμ¬ ν΄λ μμ μ½μ μ μκ² ν λΏμ λλ€. μ§μλ₯Ό μ¦λͺ νλ €λ©΄ λΉλ°ν€ λλ 곡κ°ν€λ‘ μλͺ κ²μ¦μ ν΄μΌ νλ©° μ΄ λꡬλ κ·Έ λ¨κ³λ₯Ό μννμ§ μμ΅λλ€. κ²μ¦λμ§ μμ ν ν°μ ν΄λ μμ μ λ μ λ’°νμ§ λ§μΈμ.
JWT νμ΄λ‘λλ μνΈνλμ΄ μλμ?
μλλλ€. νμ€ JWT νμ΄λ‘λλ μνΈνκ° μλλΌ base64urlλ‘ μΈμ½λ©λ κ°μ΄λ―λ‘ ν ν°μ κ°μ§ λꡬλ μ½μ μ μμ΅λλ€. λ―Όκ°ν λ°μ΄ν°λ λ³λμ JSON Web Encryption(JWE) ν ν°μ μ°μ§ μλ ν JWT νμ΄λ‘λμ λλ©΄ μ λ©λλ€.
νμ΄λ‘λμ μΌλ°μ μΈ ν΄λ μμ?
νμ€ λ±λ‘ ν΄λ μμΌλ‘ sub(μ λͺ©), iss(λ°κΈμ), aud(μμ μ), exp(λ§λ£ μκ°), iat(λ°κΈ μκ°), nbf(μμ μκ°)κ° μμΌλ©°, μ ν리μΌμ΄μ
κ³ μ μ 컀μ€ν
ν΄λ μλ ν¨κ» λ€μ΄κ° μ μμ΅λλ€.
ν ν°μ΄ λμ½λ©μ μ€ν¨νλ μ΄μ λ?
κ°μ₯ νν μμΈμ ν ν°μ΄ μλ¦° κ²½μ°, μΈ λ²μ§Έ(μλͺ ) μΈκ·Έλ¨ΌνΈκ° λλ½λ κ²½μ°, 볡μ¬-λΆμ¬λ£κΈ° κ³Όμ μ 곡백, λλ λ¨μ μλͺ μ΄ μλλΌ μνΈνλ JWE ν ν°μΈ κ²½μ°μ λλ€. μ΄ λꡬλ μ μΌλ‘ ꡬλΆλ base64url μΈ λΆλΆμ μ νν κΈ°λν©λλ€.
μ ν ν°μ΄ μλ²λ‘ μ μ‘λλμ?
μλλλ€. λͺ¨λ λμ½λ©μ λΈλΌμ°μ μμ λ‘μ»¬λ‘ μ€νλλ―λ‘ μ€μ μ‘μΈμ€ ν ν°κ³Ό μ격μ¦λͺ μ΄ κΈ°κΈ°λ₯Ό λ λμ§ μμ΅λλ€. κ·Έλμ μ€μ μΈμ¦ ν ν°μ κ²μ¬νκΈ°μλ μμ ν©λλ€.