JWT Decoder
Decode a JSON Web Token to see its header, payload and claims, with human-readable issued-at and expiry times. The token is decoded in your browser and never sent anywhere.
This tool runs entirely in your browser.
How to use the JWT Decoder
- 1Paste a JWT (the “Bearer ” prefix is removed automatically).
- 2Read the decoded header and payload.
- 3Check the expiry status and timestamps.
What is the JWT Decoder?
A JWT has three Base64URL-encoded parts separated by dots: a header (algorithm and type), a payload (claims such as sub, exp and iat) and a signature. Decoding reveals the header and payload; it does not prove the token is genuine.
Pasting production tokens into online tools that send them to a server is a security risk. This decoder works entirely offline in your browser.
Frequently asked questions
Does this verify the signature?
No. Verifying a signature requires the secret or public key. Never trust a decoded payload without verifying it on your server.
Are JWTs encrypted?
Standard signed JWTs (JWS) are only encoded, so anyone can read the payload. Do not put secrets in them.
Is the JWT Decoder free and private?
Yes. The JWT Decoder is free, needs no account, and runs entirely in your browser. What you type is never sent to a server or stored.
Related tools
All developer tools →- Base64 DecoderDecode Base64 to text.
- JSON FormatterFormat and beautify JSON online.
- Unix Timestamp ConverterConvert Unix epoch time to dates and back.
- Hash GeneratorGenerate MD5, SHA-1, SHA-256 and SHA-512 hashes.
- JSON ValidatorCheck if JSON is valid and find syntax errors.
- JSON MinifierRemove whitespace to make JSON compact.
