Is It Safe to Paste a JWT Into an Online Decoder?

📄 6 min readUpdated October 12, 2026

It's safe if the decoder runs entirely in your browser and the token is expired or from a test system. It's risky if you paste a live production token into a site that sends it to a server. A JWT isn't just data about a login. It often is the login, and whoever holds it can use it until it expires. Our JWT Decoder splits and decodes the token on your device with no network request. Below is how to check any other decoder, what's actually inside a token, and what to do if you've already pasted one somewhere you shouldn't have.

Why is pasting a JWT different from pasting other text?

Most JWTs are bearer tokens. The server that issued one doesn't check who's presenting it. It checks the signature and the expiry, and if both pass, the request goes through. So a valid access token copied from your browser's dev tools works just as well from somebody else's laptop.

That's the real risk with online decoders. Decoding itself is harmless, because the payload was never secret. The danger is a copy of a still-valid credential ending up in someone's server logs, analytics or error reports.

Is the data inside a JWT encrypted?

No, not in the usual kind. A JWT, defined in RFC 7519, is three base64url-encoded segments joined by dots: header, payload and signature. Base64url is an encoding, not encryption, so anyone with the token can read every claim in it. The signature only proves the token hasn't been changed since the issuer signed it. It doesn't hide anything.

There is an encrypted variant, JSON Web Encryption (RFC 7516), and you can spot it by counting dots. A signed token has three parts. An encrypted one has five, and its payload decodes to gibberish without the key.

What can someone learn from a decoded JWT?

The standard claims, listed in RFC 7519 section 4.1, are mostly harmless on their own. The custom claims that apps add are where personal data turns up.

ClaimMeaningSensitive?
issWho issued the tokenLow. Reveals your identity provider or domain
subThe user or account IDMedium. A stable ID that can link activity
audWhich API the token is forLow
expExpiry time, in Unix secondsNo, but tells an attacker how long it works
nbf / iatNot-before and issued-at timesNo
jtiA unique token IDNo
email, name, roles, tenantCustom claims added by the appOften high. Personal data and permissions

How do I check whether a decoder sends my token anywhere?

  1. Open the decoder page and press F12 (or Cmd+Option+I on a Mac) to open developer tools.
  2. Click the Network tab and clear it so it's empty.
  3. Paste a token. A test one is fine.
  4. Watch the list. A client-side decoder adds nothing, or only ad and analytics requests that don't contain the token. If you see a request carrying your token in its URL or body, the site is sending it to a server.

Don't rely on a "we never store your token" line alone. When we checked in October 2026, jwt.io, the best-known decoder (run by Auth0, part of Okta), didn't state on its home page whether processing happens in the browser. It may well be client-side, but the network tab is how you'd know for sure.

Can I decode a JWT without any website?

Yes, and for production tokens that's the safest route. With Python installed, this prints the payload:

python3 -c "import base64,json,sys; p=sys.argv[1].split('.')[1]; print(json.loads(base64.urlsafe_b64decode(p+'='*(-len(p)%4))))" YOUR_TOKEN

The '='*(-len(p)%4) part restores the padding that base64url strips off. Plain base64 -d in a terminal usually prints the payload but complains about that missing padding, which is why the Python version is tidier. You can also run any base64url segment through our Base64 Encoder with URL-safe mode on, and tidy the result with the JSON Formatter. Both run locally too.

What do the exp and iat numbers mean?

They're Unix timestamps: seconds since January 1, 1970, UTC. Our decoder converts them to your local time. Here are some reference points if you're reading one by hand:

TimestampDate and time (UTC)
1700000000November 14, 2023, 22:13
1735689600January 1, 2025, 00:00
1767225600January 1, 2026, 00:00
1800000000January 15, 2027, 08:00
2000000000May 18, 2033, 03:33
2147483647January 19, 2038, 03:14 (the 32-bit limit)

Subtract iat from exp to get the token's lifetime in seconds. 3600 is one hour and 86400 is one day. A long-lived access token is a bigger problem if it leaks, which is worth raising with whoever runs the API.

Does decoding a JWT tell me it's valid?

No. Decoding reads the claims, and validating means checking the signature against the issuer's key. Our decoder shows a green "VALID" or red "EXPIRED" badge, but that badge only compares exp to your clock. It doesn't check the signature, and a forged token with a future expiry would show green too. RFC 8725, the JWT best-practices document, warns servers never to trust a token's own alg header without checking it against an allowed list. That rule exists because of exactly this kind of confusion.

Signature checks are where pasting gets riskier. To verify an HS256 token, a tool needs the shared secret, and that secret can mint new tokens for every user. Never paste a production HMAC secret into a website. RS256 and ES256 tokens verify with a public key, which is fine to share.

What should I do if I pasted a live token online?

Hashing is a different job from signing, but if you're comparing secrets or fingerprints, our Hash Generator also runs offline. For more no-upload tools, see the best free privacy tools.

Frequently Asked Questions

Is it safe to paste a JWT into jwt.io?

For expired or test tokens, yes. For live production tokens, check first: open developer tools, watch the Network tab and paste a test token to see whether it's sent anywhere. In October 2026 jwt.io's home page didn't say whether decoding happens in the browser, so the network check is the reliable way to know.

Can someone use my JWT if they see it?

Usually, yes, until it expires. Most JWTs are bearer tokens, so the server accepts them from whoever presents them as long as the signature is valid and the exp time hasn't passed.

Is a JWT payload encrypted?

Not in a normal signed JWT. The header and payload are base64url-encoded, which anyone can decode. Only JSON Web Encryption tokens, which have five dot-separated parts instead of three, hide the payload.

Does decoding a JWT verify it?

No. Decoding just reads the header and payload. Verification checks the signature with the issuer's secret or public key. A decoder that labels a token valid based only on the exp claim hasn't checked the signature.

What should I do if I leaked a JWT?

Sign out or revoke the session so the refresh token stops working, and note when the access token's exp claim runs out. If a signing secret leaked, rotate it right away so tokens signed with it are rejected.

Related Tools