JWT Decoder

Decode JWT (JSON Web Token) header, payload, and signature to inspect claims.

πŸ“– How to Use

1
Enter JWT

Paste the JWT token you want to decode. e.g. eyJhbGciOiJIUzI1NiIs...

2
Decode

Click πŸ”“ Decode to split and display the header, payload, and signature.

3
Copy Result

Use πŸ“‹ Copy buttons to save the header or payload to clipboard.

πŸ’‘ Tip: JWTs are commonly used for server authentication. The payload is Base64Url-encoded and readable by anyone, but only the signature can verify tampering.

About the JWT Decoder

A JSON Web Token (JWT, RFC 7519) is a compact, URL-safe string used to assert claims between two parties, most commonly as a bearer credential after a user signs in to a web or mobile application. A JWT encodes a small JSON object that the server can read to identify a user, their roles, and an expiration, without a database lookup on every request. This decoder lets you inspect the contents of a token — its header, payload, and signature — entirely in your browser, which is exactly what you need when debugging authentication failures.

How it works

A JWT has three base64url-encoded parts joined by dots: header.payload.signature. The header declares the token type (typ) and the signing algorithm (alg, for example HS256 or RS256). The payload carries the claims — standard ones like sub (subject), exp (expiration), iat (issued-at), iss (issuer), and aud (audience), plus any custom claims. The signature is computed by the issuer over the base64url of the header and payload using the algorithm from the header and a secret (HMAC) or private key (RSA/ECDSA).

Base64url is the variant this tool must handle: it replaces + with - and / with _, and omits the = padding, so the token is safe inside URLs and headers. Decoding is just reversing that and parsing JSON — it is reading, not security. The critical distinction: decoding reveals the payload to anyone who has the token (a JWT is signed, not encrypted); only signature verification against the secret or public key proves the token was not tampered with. This tool decodes and reads only — it does not verify signatures, so never trust claims from an unverified token.

Common use cases

  • Inspecting a token returned by an OAuth2 or OpenID Connect server
  • Debugging an expired exp or wrong aud causing 401 responses
  • Auditing which claims and scopes an identity provider actually issued
  • Verifying the alg header before implementing server-side verification
  • Teaching how the three-part structure maps to header, payload, and signature

Worked example

Given this (unsigned, sample) token:

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkFkYSBMb3ZlbGFjZSIsImlhdCI6MTczNTY4OTYwMCwiZXhwIjoxNzM1Nzc2MDAwfQ.sOmE_s1gN0tBp2xV7l3oFakeSig

Decoding the first segment yields the header:

{ "alg": "HS256", "typ": "JWT" }

And the second segment yields the payload:

{
  "sub": "1234567890",
  "name": "Ada Lovelace",
  "iat": 1735689600,
  "exp": 1735776000
}

Anyone can reproduce this output from the token — that is why a JWT must never contain secrets, and why you must verify the signature before acting on the claims.

Frequently asked questions

Does decoding a JWT verify its signature?

No. Decoding only base64url-decodes the header and payload so you can read the claims. Proving authenticity requires signature verification against the secret or public key, which this tool does not perform. Never trust claims from an unverified token.

Is the JWT payload encrypted?

No. A standard JWT payload is base64url-encoded, not encrypted, so anyone who has the token can read it. Sensitive data must never be placed in a JWT payload unless you use a separate JSON Web Encryption (JWE) token.

What are the common payload claims?

Standard registered claims include sub (subject), iss (issuer), aud (audience), exp (expiration time), iat (issued-at time), and nbf (not-before time). Custom application-specific claims can also appear alongside them.

Why does my token fail to decode?

The most common causes are a truncated token, a missing third (signature) segment, copy-paste whitespace, or a JWE token that is encrypted rather than merely signed. The tool expects exactly three base64url parts separated by dots.

Is my token sent to a server?

No. All decoding runs locally in your browser, so live access tokens and credentials never leave your device. This makes the tool safe for inspecting real authentication tokens.

JWT λ””μ½”λ”λž€?

JSON Web Token(JWT, RFC 7519)은 두 주체 간에 ν΄λ ˆμž„μ„ μ „λ‹¬ν•˜κΈ° μœ„ν•΄ μ‚¬μš©ν•˜λŠ” κ°„κ²°ν•˜κ³  URL에 μ•ˆμ „ν•œ λ¬Έμžμ—΄λ‘œ, 주둜 μ‚¬μš©μžκ°€ μ›Ήμ΄λ‚˜ λͺ¨λ°”일 μ• ν”Œλ¦¬μΌ€μ΄μ…˜μ— λ‘œκ·ΈμΈν•œ λ’€ μ „λ‹¬ν•˜λŠ” λ² μ–΄λŸ¬ 자격증λͺ…μœΌλ‘œ μ“°μž…λ‹ˆλ‹€. JWTλŠ” μž‘μ€ JSON 객체λ₯Ό μΈμ½”λ”©ν•˜μ—¬ μ„œλ²„κ°€ λ§€ μš”μ²­λ§ˆλ‹€ λ°μ΄ν„°λ² μ΄μŠ€λ₯Ό μ‘°νšŒν•˜μ§€ μ•Šκ³ λ„ μ‚¬μš©μžμ™€ μ—­ν• , 만료 μ‹œκ°„μ„ 식별할 수 있게 ν•΄ μ€λ‹ˆλ‹€. 이 λ””μ½”λ”λŠ” ν† ν°μ˜ λ‚΄μš© — 헀더, νŽ˜μ΄λ‘œλ“œ, μ„œλͺ… — 을 μ „μ μœΌλ‘œ λΈŒλΌμš°μ € μ•ˆμ—μ„œ 검사할 수 있게 ν•΄ μ£Όλ©°, 인증 μ‹€νŒ¨λ₯Ό λ””λ²„κΉ…ν•˜κ±°λ‚˜ μ„œλ²„κ°€ μ‹€μ œλ‘œ λ°œκΈ‰ν•œ λ‚΄μš©μ„ 감사할 λ•Œ ν•„μš”ν•œ λ„κ΅¬μž…λ‹ˆλ‹€.

μž‘λ™ 방식

JWTλŠ” base64url둜 μΈμ½”λ”©λœ μ„Έ 뢀뢄을 점으둜 이어 뢙인 header.payload.signature ν˜•νƒœμž…λ‹ˆλ‹€. ν—€λ”λŠ” 토큰 μœ ν˜•(typ)κ³Ό μ„œλͺ… μ•Œκ³ λ¦¬μ¦˜(alg, 예: HS256, RS256)을 μ„ μ–Έν•©λ‹ˆλ‹€. νŽ˜μ΄λ‘œλ“œλŠ” ν΄λ ˆμž„μ„ λ‹΄μŠ΅λ‹ˆλ‹€ — sub(제λͺ©), exp(만료), iat(λ°œκΈ‰ μ‹œκ°), iss(λ°œκΈ‰μž), aud(μˆ˜μ‹ μž) 같은 ν‘œμ€€ ν΄λ ˆμž„κ³Ό μž„μ˜μ˜ μ»€μŠ€ν…€ ν΄λ ˆμž„μž…λ‹ˆλ‹€. μ„œλͺ…은 λ°œκΈ‰μžκ°€ 헀더와 νŽ˜μ΄λ‘œλ“œμ˜ base64url에 λŒ€ν•΄ 헀더에 λͺ…μ‹œλœ μ•Œκ³ λ¦¬μ¦˜κ³Ό λΉ„λ°€ν‚€(HMAC) λ˜λŠ” κ°œμΈν‚€(RSA/ECDSA)둜 κ³„μ‚°ν•©λ‹ˆλ‹€.

Base64url은 이 도ꡬ가 λ°˜λ“œμ‹œ 닀뀄야 ν•˜λŠ” λ³€ν˜•μž…λ‹ˆλ‹€. + λŒ€μ‹  -λ₯Ό, / λŒ€μ‹  _λ₯Ό μ“°κ³  = νŒ¨λ”©μ„ μƒλž΅ν•˜μ—¬ 토큰이 URLκ³Ό 헀더에 듀어가도 μ•ˆμ „ν•©λ‹ˆλ‹€. 디코딩은 이λ₯Ό μ—­μœΌλ‘œ 되돌리고 JSON을 νŒŒμ‹±ν•˜λŠ” 것일 뿐, 읽기이지 λ³΄μ•ˆμ΄ μ•„λ‹™λ‹ˆλ‹€. 핡심적인 ꡬ뢄: 디코딩은 토큰을 κ°€μ§„ λˆ„κ΅¬λ‚˜ νŽ˜μ΄λ‘œλ“œλ₯Ό λ³Ό 수 있게 ν•©λ‹ˆλ‹€(JWTλŠ” μ•”ν˜Έν™”κ°€ μ•„λ‹ˆλΌ μ„œλͺ…λœ κ°’μž…λ‹ˆλ‹€). μ„œλͺ… κ²€μ¦λ§Œμ΄ λΉ„λ°€ν‚€ λ˜λŠ” κ³΅κ°œν‚€λ‘œ 토큰이 λ³€μ‘°λ˜μ§€ μ•Šμ•˜κ³  μ§„μ§œ λ°œκΈ‰μžμ—κ²Œμ„œ μ™”μŒμ„ 증λͺ…ν•©λ‹ˆλ‹€. 이 λ„κ΅¬λŠ” λ””μ½”λ”©/읽기만 ν•˜κ³  μ„œλͺ…을 κ²€μ¦ν•˜μ§€ μ•ŠμœΌλ―€λ‘œ, κ²€μ¦λ˜μ§€ μ•Šμ€ ν† ν°μ˜ ν΄λ ˆμž„μ€ μ ˆλŒ€ μ‹ λ’°ν•˜μ§€ λ§ˆμ„Έμš”.

자주 μ“°λŠ” 경우

  • OAuth2 λ˜λŠ” OpenID Connect μ„œλ²„κ°€ λ°˜ν™˜ν•œ 토큰 검사
  • 만료된 exp λ˜λŠ” 잘λͺ»λœ aud둜 μΈν•œ 401 응닡 디버깅
  • ID κ³΅κΈ‰μžκ°€ μ‹€μ œλ‘œ λ°œκΈ‰ν•œ ν΄λ ˆμž„κ³Ό μŠ€μ½”ν”„ 감사
  • μ„œλ²„ μΈ‘ 검증을 κ΅¬ν˜„ν•˜κΈ° μ „ alg 헀더 확인
  • μ„Έ λΆ€λΆ„ ꡬ쑰가 헀더, νŽ˜μ΄λ‘œλ“œ, μ„œλͺ…에 μ–΄λ–»κ²Œ λŒ€μ‘λ˜λŠ”μ§€ ν•™μŠ΅

μ‚¬μš© 예

λ‹€μŒ (μ„œλͺ…λ˜μ§€ μ•Šμ€ μ˜ˆμ‹œ) 토큰이 μ£Όμ–΄μ§€λ©΄:

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkFkYSBMb3ZlbGFjZSIsImlhdCI6MTczNTY4OTYwMCwiZXhwIjoxNzM1Nzc2MDAwfQ.sOmE_s1gN0tBp2xV7l3oFakeSig

첫 번째 μ„Έκ·Έλ¨ΌνŠΈλ₯Ό λ””μ½”λ”©ν•˜λ©΄ 헀더가 λ‚˜μ˜΅λ‹ˆλ‹€:

{ "alg": "HS256", "typ": "JWT" }

두 번째 μ„Έκ·Έλ¨ΌνŠΈλŠ” νŽ˜μ΄λ‘œλ“œλ₯Ό λ°˜ν™˜ν•©λ‹ˆλ‹€:

{
  "sub": "1234567890",
  "name": "Ada Lovelace",
  "iat": 1735689600,
  "exp": 1735776000
}

λˆ„κ΅¬λ‚˜ ν† ν°μ—μ„œ 이 좜λ ₯을 μž¬ν˜„ν•  수 μžˆμŠ΅λ‹ˆλ‹€ — κ·Έλž˜μ„œ JWT에 비밀을 λ‹΄μœΌλ©΄ μ•ˆ 되며, ν΄λ ˆμž„μ— μ˜μ‘΄ν•΄ ν–‰λ™ν•˜κΈ° 전에 λ°˜λ“œμ‹œ μ„œλͺ…을 검증해야 ν•©λ‹ˆλ‹€.

자주 λ¬»λŠ” 질문

JWTλ₯Ό λ””μ½”λ”©ν•˜λ©΄ μ„œλͺ…이 κ²€μ¦λ˜λ‚˜μš”?

μ•„λ‹™λ‹ˆλ‹€. 디코딩은 헀더와 νŽ˜μ΄λ‘œλ“œλ₯Ό base64url λ””μ½”λ”©ν•˜μ—¬ ν΄λ ˆμž„μ„ 읽을 수 있게 ν•  λΏμž…λ‹ˆλ‹€. μ§„μœ„λ₯Ό 증λͺ…ν•˜λ €λ©΄ λΉ„λ°€ν‚€ λ˜λŠ” κ³΅κ°œν‚€λ‘œ μ„œλͺ… 검증을 ν•΄μ•Ό ν•˜λ©° 이 λ„κ΅¬λŠ” κ·Έ 단계λ₯Ό μˆ˜ν–‰ν•˜μ§€ μ•ŠμŠ΅λ‹ˆλ‹€. κ²€μ¦λ˜μ§€ μ•Šμ€ ν† ν°μ˜ ν΄λ ˆμž„μ€ μ ˆλŒ€ μ‹ λ’°ν•˜μ§€ λ§ˆμ„Έμš”.

JWT νŽ˜μ΄λ‘œλ“œλŠ” μ•”ν˜Έν™”λ˜μ–΄ μžˆλ‚˜μš”?

μ•„λ‹™λ‹ˆλ‹€. ν‘œμ€€ JWT νŽ˜μ΄λ‘œλ“œλŠ” μ•”ν˜Έν™”κ°€ μ•„λ‹ˆλΌ base64url둜 μΈμ½”λ”©λœ κ°’μ΄λ―€λ‘œ 토큰을 κ°€μ§„ λˆ„κ΅¬λ‚˜ 읽을 수 μžˆμŠ΅λ‹ˆλ‹€. λ―Όκ°ν•œ λ°μ΄ν„°λŠ” λ³„λ„μ˜ JSON Web Encryption(JWE) 토큰을 μ“°μ§€ μ•ŠλŠ” ν•œ JWT νŽ˜μ΄λ‘œλ“œμ— 두면 μ•ˆ λ©λ‹ˆλ‹€.

νŽ˜μ΄λ‘œλ“œμ˜ 일반적인 ν΄λ ˆμž„μ€?

ν‘œμ€€ 등둝 ν΄λ ˆμž„μœΌλ‘œ sub(제λͺ©), iss(λ°œκΈ‰μž), aud(μˆ˜μ‹ μž), exp(만료 μ‹œκ°), iat(λ°œκΈ‰ μ‹œκ°), nbf(μ‹œμž‘ μ‹œκ°)κ°€ 있으며, μ• ν”Œλ¦¬μΌ€μ΄μ…˜ 고유의 μ»€μŠ€ν…€ ν΄λ ˆμž„λ„ ν•¨κ»˜ λ“€μ–΄κ°ˆ 수 μžˆμŠ΅λ‹ˆλ‹€.

토큰이 디코딩에 μ‹€νŒ¨ν•˜λŠ” μ΄μœ λŠ”?

κ°€μž₯ ν”ν•œ 원인은 토큰이 잘린 경우, μ„Έ 번째(μ„œλͺ…) μ„Έκ·Έλ¨ΌνŠΈκ°€ λˆ„λ½λœ 경우, 볡사-λΆ™μ—¬λ„£κΈ° κ³Όμ •μ˜ 곡백, λ˜λŠ” λ‹¨μˆœ μ„œλͺ…이 μ•„λ‹ˆλΌ μ•”ν˜Έν™”λœ JWE 토큰인 κ²½μš°μž…λ‹ˆλ‹€. 이 λ„κ΅¬λŠ” 점으둜 κ΅¬λΆ„λœ base64url μ„Έ 뢀뢄을 μ •ν™•νžˆ κΈ°λŒ€ν•©λ‹ˆλ‹€.

제 토큰이 μ„œλ²„λ‘œ μ „μ†‘λ˜λ‚˜μš”?

μ•„λ‹™λ‹ˆλ‹€. λͺ¨λ“  디코딩은 λΈŒλΌμš°μ €μ—μ„œ 둜컬둜 μ‹€ν–‰λ˜λ―€λ‘œ μ‹€μ œ μ•‘μ„ΈμŠ€ 토큰과 자격증λͺ…이 κΈ°κΈ°λ₯Ό λ– λ‚˜μ§€ μ•ŠμŠ΅λ‹ˆλ‹€. κ·Έλž˜μ„œ μ‹€μ œ 인증 토큰을 κ²€μ‚¬ν•˜κΈ°μ—λ„ μ•ˆμ „ν•©λ‹ˆλ‹€.