Developer Tools

JWT Decoder

Decode a JWT header and payload in your browser and read expiry, issued-at, and claims. The signature is not verified. Free, fast, and built for a clean browser workflow.

Decoded locally. The signature is not verified.

Status

Paste a token to decode the header and payload.

About this tool

A JSON Web Token has three segments: header, payload, and signature. This decoder Base64URL-decodes the first two so you can read the algorithm and claims.

Decoding does not prove the token is authentic. The signature is shown but not checked, because verification needs the issuer's secret or public key.

The token stays in your browser. Avoid pasting long-lived production tokens on a shared computer, and clear the page when you are done.

Tips for better results

  • exp, iat, and nbf are Unix timestamps in seconds. The tool shows them as local dates when they are present.
  • A token with alg none, or a missing signature segment, still decodes. Treat that as a reason to inspect the issuer, not as proof the token is valid.
  • Use this to debug expiry and claims during development. Confirm signatures in your API with the real key.
  • Never publish a decoded token that contains emails, user ids, or session data.

How to use

  1. 1 Paste a JWT (three Base64URL segments separated by dots).
  2. 2 Read the decoded header and payload.
  3. 3 Check the expiry time if the token includes an exp claim.

FAQ

Does this verify the signature?

No. It only decodes the header and payload. Verification needs the signing key on your server.

Is the token uploaded?

No. Decoding uses the browser's Base64 and JSON parsers.

Why does expiry show a local time?

exp is a UTC Unix timestamp. The page formats it in your computer's time zone.

What if the token is malformed?

The page explains which segment failed to decode instead of showing partial garbage as valid JSON.

Can I decode encrypted JWTs (JWE)?

No. This page reads signed JWS tokens with a JSON header and payload, not encrypted JWE tokens.

Should I paste a production access token?

Prefer short-lived dev tokens. The value stays local, but anyone who can see your screen can read the claims.