JWT Decoder

Decode JSON Web Tokens and inspect their header, payload, and claims.

⚠️ Decode ≠ Verify. This tool decodes the JWT but does NOT verify its signature. Never trust a JWT just because it decodes.

What is a JWT?

A JSON Web Token (JWT) is a compact, URL-safe token used for authentication and authorization. It consists of three Base64URL-encoded parts separated by dots:header.payload.signature.

Decode ≠ Verify

Decoding extracts the header and payload — anyone can do it.Verifying proves the token was signed by a trusted party using a secret or public key. A decoded token is not a trusted token. Always verify on the server before trusting a JWT.

How to use this tool

  1. Paste your JWT token into the input.
  2. Header and payload are decoded automatically.
  3. Registered claims (exp, iat, nbf) are shown with human-readable dates.
  4. Use the Copy buttons to copy the decoded JSON.

Privacy

Your JWT is decoded entirely in your browser. Nothing is uploaded to any server.

Frequently Asked Questions

Is this JWT Decoder free?

Yes, completely free. No signup, no limits.

Is my token uploaded to a server?

No. Decoding happens entirely in your browser. Your JWT never leaves your device.

Does this tool verify the signature?

No. It only decodes the header and payload. Verification requires the secret key (HS256) or public key (RS256), which this tool does not have. Decode ≠ Verify.

What does 'expired' mean?

If the token's exp (expiration) claim is in the past, it's expired and should not be accepted by a server.

What is a JWT?

JSON Web Token (JWT) is a compact, URL-safe way to represent claims between two parties. It has three parts: header.payload.signature, each Base64URL encoded.

Related Tools