Emojar – free online tools

JWT Decoder

Decode a JSON Web Token to see its header, payload and claims, with human-readable issued-at and expiry times. The token is decoded in your browser and never sent anywhere.

This tool runs entirely in your browser.

Loading tool…

How to use the JWT Decoder

  1. 1Paste a JWT (the “Bearer ” prefix is removed automatically).
  2. 2Read the decoded header and payload.
  3. 3Check the expiry status and timestamps.

What is the JWT Decoder?

A JWT has three Base64URL-encoded parts separated by dots: a header (algorithm and type), a payload (claims such as sub, exp and iat) and a signature. Decoding reveals the header and payload; it does not prove the token is genuine.

Pasting production tokens into online tools that send them to a server is a security risk. This decoder works entirely offline in your browser.

Frequently asked questions

Does this verify the signature?

No. Verifying a signature requires the secret or public key. Never trust a decoded payload without verifying it on your server.

Are JWTs encrypted?

Standard signed JWTs (JWS) are only encoded, so anyone can read the payload. Do not put secrets in them.

Is the JWT Decoder free and private?

Yes. The JWT Decoder is free, needs no account, and runs entirely in your browser. What you type is never sent to a server or stored.