JWT Decoder
Decode a JWT to inspect its header, payload and expiry — entirely in your browser.
How to use
- Paste your JWT.
- The header and payload are decoded and pretty-printed.
- If there's an expiry claim, you'll see whether the token is still valid.
How the JWT Decoder works
Decodes a JSON Web Token so you can read its header and claims — essential when debugging authentication that is failing for reasons the error message will not tell you.
A JWT is three Base64url-encoded segments joined by dots: header, payload and signature. This tool decodes the first two and displays them as formatted JSON. Registered claims such as exp and iat are Unix timestamps.
header.payload.signature (each segment Base64url-encoded)
Worked example
A payload might decode to {"sub":"1234567890","name":"Jane","iat":1516239022,"exp":1516242622} — issued and expiring an hour apart.
Things worth knowing
- Decoding is not verifying. Anyone can read a JWT's contents; only the server holding the secret or public key can confirm the signature is genuine.
- Never put secrets in a JWT payload. It is encoded, not encrypted, and is trivially readable by anyone who intercepts it.
- Everything happens in your browser — the token is not transmitted, which matters given tokens are credentials.
Frequently asked questions
Does this verify the signature?
No — decoding only reveals the contents. Verifying the signature needs the secret or public key, which stays on your server.
Is my token sent anywhere?
No — decoding happens entirely in your browser, so your token is never transmitted.
Why is my token rejected even though it looks correct?
Most often expiry — check the exp claim against current time — or a clock skew, audience or issuer mismatch.
Is it safe to paste a real token here?
It is decoded locally and never leaves the page. Still, treat production tokens as live credentials and rotate anything you have shared elsewhere.