JWT Decoder
Decode JSON Web Token header and payload (no verification). Free, private and instant.
About the JWT Decoder
A JSON Web Token has a header, a payload of claims and a signature. The first two parts are only Base64-encoded, so anyone can read them.
When to use it
Use it to inspect expiry, user ID and scopes while debugging auth. Decoding does not verify the signature, so never trust it alone.
Structure of a JWT
A JSON Web Token has three Base64URL parts separated by dots: header, payload and signature. The header names the signing algorithm, and the payload holds claims such as sub, iat and exp.
Common claims
exp is the expiry time, iat is when the token was issued, nbf means not before, iss is the issuer, aud is the audience and sub is the subject. Times are Unix timestamps in seconds, which the timestamp converter can read.
Decoding is not verifying
Anyone can read a token payload, and decoding does not prove the token is genuine. Only a server that holds the key can verify the signature. Never put passwords or secrets in a JWT payload.
Debugging tips
If requests fail with 401, check exp first, then the audience and issuer. Clock differences between servers can make a fresh token look expired.
How to use the JWT Decoder
- Enter or paste your input in the fields above.
- The result updates as you type, or press Run.
- Press Copy to copy the output.
Frequently asked questions
Is the JWT Decoder free?
Yes. It is completely free, with no signup and no usage limits.
Is my data uploaded anywhere?
No. Everything runs locally in your browser, so what you type never leaves your device.
Does the JWT Decoder work on mobile?
Yes. The tool is responsive and works on phones, tablets and desktops.
More free tools
Generate strong random passwords using the Web Crypto API.
Security•••SHA Hash GeneratorGenerate SHA-1, SHA-256 or SHA-512 hashes locally.
Security•••Password Strength CheckerEstimate password strength and entropy without sending it anywhere.
Security•••HMAC GeneratorCreate HMAC signatures with SHA-256, SHA-1 or SHA-512.
Security•••Random Token & API Key GeneratorGenerate secure random tokens in hex or base64url.
Security•••Caesar Cipher / ROT13Encode or decode text with a Caesar shift. For learning, not real security.
Security