Skip to content
ToolsOnDuty - free online tools
Security & Cryptography

JWT Decoder

Decode a JSON Web Token to inspect its header and payload.

Free browser toolRuns in your browserNo sign-up

The signature is not verified. This tool only decodes the token, so never trust a JWT based on decoding alone. Everything runs in your browser.

Glossary

Header
The first part, listing the signing algorithm and token type.
Payload
The middle part, holding the claims (the data) about the user or session.
Signature
The last part, used to verify the token was not changed. This tool does not check it.
iss (issuer)
Who created and signed the token.
sub (subject)
Who or what the token is about, often a user ID.
aud (audience)
Who the token is intended for.
exp (expires)
The time after which the token is no longer valid.
nbf (not before)
The time before which the token must not be accepted.
iat (issued at)
The time the token was created.

100% private - runs entirely in your browser.

Your input, keys and passwords are never uploaded. Want proof? Load this page, then turn off your internet - the tool still works. For an exact check, open your browser's DevTools Network tab and confirm no data is sent when you use it.

About the JWT Decoder

A JSON Web Token (JWT) is a compact, URL-safe token made of three Base64URL parts: a header, a payload of claims, and a signature.

Paste a token and this tool decodes the header and payload so you can inspect the claims, and it shows the issued, not-before and expiry times in a readable format.

Decoding happens entirely in your browser and the token is never uploaded, which matters because tokens often contain sensitive session data.

Key features

  • Decodes header and payload instantly
  • Human-readable iat, nbf and exp times
  • Handles standard Base64URL encoding
  • Runs locally, nothing is uploaded

How to use

  1. 1Paste your JWT into the box.
  2. 2The decoded header and payload appear immediately.
  3. 3Check the readable timestamps for issue and expiry times.

Examples

Inspect token claims
Input: A three-part JWT
Output: Decoded header and payload JSON

Decoding does not verify the signature or prove that the claims are trustworthy.

Frequently asked questions

Does this verify the token's signature?
No. It only decodes the token so you can read it. A decoded token is not proof of authenticity, so never trust a JWT based on decoding alone.
Is my token sent to a server?
No. Decoding happens entirely in your browser, so your token and its claims never leave your device.
Why is the payload readable if it is 'encoded'?
JWTs are encoded, not encrypted. The header and payload are just Base64URL text, so anyone can read them. Sensitive data should not be placed in a JWT payload.

Open a related tool to prepare your files or refine the finished result.