Home › Tools › Security › JWT Decoder

JWT Decoder

Decode JSON Web Token header and payload (no verification). Free, private and instant.

About the JWT Decoder

A JSON Web Token has a header, a payload of claims and a signature. The first two parts are only Base64-encoded, so anyone can read them.

When to use it

Use it to inspect expiry, user ID and scopes while debugging auth. Decoding does not verify the signature, so never trust it alone.

Structure of a JWT

A JSON Web Token has three Base64URL parts separated by dots: header, payload and signature. The header names the signing algorithm, and the payload holds claims such as sub, iat and exp.

Common claims

exp is the expiry time, iat is when the token was issued, nbf means not before, iss is the issuer, aud is the audience and sub is the subject. Times are Unix timestamps in seconds, which the timestamp converter can read.

Decoding is not verifying

Anyone can read a token payload, and decoding does not prove the token is genuine. Only a server that holds the key can verify the signature. Never put passwords or secrets in a JWT payload.

Debugging tips

If requests fail with 401, check exp first, then the audience and issuer. Clock differences between servers can make a fresh token look expired.

How to use the JWT Decoder

  1. Enter or paste your input in the fields above.
  2. The result updates as you type, or press Run.
  3. Press Copy to copy the output.

Frequently asked questions

Is the JWT Decoder free?

Yes. It is completely free, with no signup and no usage limits.

Is my data uploaded anywhere?

No. Everything runs locally in your browser, so what you type never leaves your device.

Does the JWT Decoder work on mobile?

Yes. The tool is responsive and works on phones, tablets and desktops.

More free tools

•••Secure Password Generator

Generate strong random passwords using the Web Crypto API.

Security
•••SHA Hash Generator

Generate SHA-1, SHA-256 or SHA-512 hashes locally.

Security
•••Password Strength Checker

Estimate password strength and entropy without sending it anywhere.

Security
•••HMAC Generator

Create HMAC signatures with SHA-256, SHA-1 or SHA-512.

Security
•••Random Token & API Key Generator

Generate secure random tokens in hex or base64url.

Security
•••Caesar Cipher / ROT13

Encode or decode text with a Caesar shift. For learning, not real security.

Security
Copied!