Glossary

JWT (JSON Web Token)

A claims token, commonly carried as a signed, three-part compact JWS.

A JSON Web Token is commonly a header, a payload and a signature, each base64url encoded and joined with dots. The header and payload are JSON, readable by anyone holding the token, because base64url is an encoding rather than encryption. Some JWT profiles use a different shape, such as an unsecured token or encrypted content, so inspect the token’s declared algorithm and type before assuming a signature is present.

A signed but unencrypted JWT payload is not a place for secrets. Anyone holding it can read its claims. A signature provides integrity only after verification with a trusted key and the expected algorithm; merely decoding the token proves nothing about who issued it.

This inspector decodes three-part compact tokens so you can examine claims such as exp and iss. It does not verify signatures, enforce expiry or establish trust. Applications must verify the signature and their required claims before authorization. Asymmetric signatures can be verified with a public key; the issuer’s private signing key is not needed for that check.