JWT Decoder
Decode JSON Web Tokens and inspect their header, payload, and claims.
What is a JWT?
A JSON Web Token (JWT) is a compact, URL-safe token used for authentication and authorization. It consists of three Base64URL-encoded parts separated by dots:header.payload.signature.
Decode ≠ Verify
Decoding extracts the header and payload — anyone can do it.Verifying proves the token was signed by a trusted party using a secret or public key. A decoded token is not a trusted token. Always verify on the server before trusting a JWT.
How to use this tool
- Paste your JWT token into the input.
- Header and payload are decoded automatically.
- Registered claims (exp, iat, nbf) are shown with human-readable dates.
- Use the Copy buttons to copy the decoded JSON.
Privacy
Your JWT is decoded entirely in your browser. Nothing is uploaded to any server.
Frequently Asked Questions
Is this JWT Decoder free?
Yes, completely free. No signup, no limits.
Is my token uploaded to a server?
No. Decoding happens entirely in your browser. Your JWT never leaves your device.
Does this tool verify the signature?
No. It only decodes the header and payload. Verification requires the secret key (HS256) or public key (RS256), which this tool does not have. Decode ≠ Verify.
What does 'expired' mean?
If the token's exp (expiration) claim is in the past, it's expired and should not be accepted by a server.
What is a JWT?
JSON Web Token (JWT) is a compact, URL-safe way to represent claims between two parties. It has three parts: header.payload.signature, each Base64URL encoded.