What is a JWT?
JSON Web Tokens (JWTs) are an open, industry standard (RFC 7519) method for representing claims securely between two parties. They are commonly used for authentication and authorization in web applications and APIs.
A JWT consists of three parts separated by dots (.):
- Header: Contains the token type (JWT) and the signing algorithm being used, such as HMAC SHA256 or RSA.
- Payload: Contains the claims, which are statements about an entity (typically, the user) and additional data like expiration time (
exp). - Signature: Used to verify the message wasn't changed along the way. It is created using the encoded header, encoded payload, a secret, and the algorithm specified in the header.
Is this tool secure?
Yes, 100% secure. OmniTools operates on a strict "Zero Server Upload" architecture. When you paste your JSON Web Token into this decoder, the parsing happens entirely within your web browser using local JavaScript.
Your sensitive tokens, authentication claims, and signatures never leave your device and are never transmitted to our backend servers. This makes it completely safe for debugging production tokens.
Why do JWTs look like gibberish?
JWTs are not encrypted by default; they are simply encoded using Base64Url encoding. This ensures that the JSON data can be safely passed in URLs, HTTP headers, and HTML form parameters without character escaping issues.
Because it's only encoded (not encrypted), anyone who intercepts the token can decode and read the payload. You should never put secret information (like passwords) inside a standard JWT payload!