JWT Decoder
Decode a JSON Web Token to inspect its header and payload.
The signature is not verified. This tool only decodes the token, so never trust a JWT based on decoding alone. Everything runs in your browser.
Glossary
- Header
- The first part, listing the signing algorithm and token type.
- Payload
- The middle part, holding the claims (the data) about the user or session.
- Signature
- The last part, used to verify the token was not changed. This tool does not check it.
- iss (issuer)
- Who created and signed the token.
- sub (subject)
- Who or what the token is about, often a user ID.
- aud (audience)
- Who the token is intended for.
- exp (expires)
- The time after which the token is no longer valid.
- nbf (not before)
- The time before which the token must not be accepted.
- iat (issued at)
- The time the token was created.
100% private - runs entirely in your browser.
Your input, keys and passwords are never uploaded. Want proof? Load this page, then turn off your internet - the tool still works. For an exact check, open your browser's DevTools Network tab and confirm no data is sent when you use it.
About the JWT Decoder
A JSON Web Token (JWT) is a compact, URL-safe token made of three Base64URL parts: a header, a payload of claims, and a signature.
Paste a token and this tool decodes the header and payload so you can inspect the claims, and it shows the issued, not-before and expiry times in a readable format.
Decoding happens entirely in your browser and the token is never uploaded, which matters because tokens often contain sensitive session data.
Key features
- Decodes header and payload instantly
- Human-readable iat, nbf and exp times
- Handles standard Base64URL encoding
- Runs locally, nothing is uploaded
How to use
- 1Paste your JWT into the box.
- 2The decoded header and payload appear immediately.
- 3Check the readable timestamps for issue and expiry times.
Examples
A three-part JWTDecoded header and payload JSONDecoding does not verify the signature or prove that the claims are trustworthy.
Frequently asked questions
- Does this verify the token's signature?
- No. It only decodes the token so you can read it. A decoded token is not proof of authenticity, so never trust a JWT based on decoding alone.
- Is my token sent to a server?
- No. Decoding happens entirely in your browser, so your token and its claims never leave your device.
- Why is the payload readable if it is 'encoded'?
- JWTs are encoded, not encrypted. The header and payload are just Base64URL text, so anyone can read them. Sensitive data should not be placed in a JWT payload.
Helpful guides
Continue your workflow
Open a related tool to prepare your files or refine the finished result.
- Featured toolDeveloper ToolsBase64 Encoder / Decoder
Encode text to Base64 or decode Base64 back to text.
Open tool - Security & CryptographyHash Generator
Generate MD5, SHA-1, SHA-2 and SHA-3 hashes from any text.
Open tool - Featured toolDeveloper ToolsUnix Timestamp Converter
Convert Unix timestamps to dates and back, in seconds or milliseconds.
Open tool
