Tools/JWT Decoder

JWT Decoder

Decode a JSON Web Token and inspect its header and payload.

JWT

Runs entirely in your browser — your data never leaves this page.

About the JWT Decoder

This JWT decoder parses a JSON Web Token and displays its header and payload as readable JSON. JWTs are compact, URL-safe tokens widely used for authentication and authorization — they consist of three Base64URL-encoded parts (header, payload, signature) separated by dots.

Paste a token to instantly inspect its claims, algorithm, and expiry. The decoder detects the "exp" claim and tells you whether the token has expired. Everything happens locally in your browser, so you can safely decode tokens without leaking them.

How to use it

  1. 1Paste your JWT into the input box.
  2. 2The header and payload are decoded and pretty-printed automatically.
  3. 3Check the expiry status shown under the payload to see if the token is still valid.
  4. 4Copy the decoded header or payload as needed.

Common use cases

  • Debugging authentication and login flows
  • Inspecting the claims and scopes inside an access token
  • Checking a token’s expiry while troubleshooting
  • Learning how JWTs are structured

Frequently asked questions

Does this JWT decoder verify the signature?

No. It only decodes the token so you can read its contents. Verifying the signature requires the secret or public key and must be done server-side. Never trust a decoded JWT’s claims without verifying its signature.

Is it safe to paste my JWT here?

The decoding happens entirely in your browser — the token is never sent anywhere. That said, treat access tokens like passwords: avoid pasting production tokens into any tool you do not control, and prefer short-lived test tokens.

Why is my token showing as expired?

The tool reads the "exp" (expiration) claim, which is a Unix timestamp. If that time is in the past, the token is expired and most servers will reject it. You will need to obtain a fresh token.