JSON Web Token (JWT) Decoder
Decode JWT headers, payload claims, and token expiration status 100% locally in your browser.
JSON Web Token (JWT) Structure & Claims Reference
JSON Web Tokens are an open, industry-standard RFC 7519 method for representing claims securely between two parties.
1. Three Token Components
JWTs consist of three dot-separated Base64URL parts: Header.Payload.Signature.
2. Expiration Verification
Inspect registered claims like exp (expiration time) and iat (issued at).
3. Privacy Protection
Decoding runs 100% in client JavaScript. Sensitive auth tokens are never logged or stored on any server.
About the JWT Decoder
The JWT Decoder splits a JSON Web Token into its three Base64URL segments and pretty-prints the header and payload. It resolves the numeric exp, iat and nbf timestamps into readable dates and flags whether the token has already expired, which is usually the fastest way to explain an unexpected 401 from an API. The signature segment is displayed but not verified, because verification requires the issuer secret or public key.
How to use the JWT Decoder
- Paste the JWT, with or without the "Bearer " prefix, into the input field.
- Read the decoded header to confirm the signing algorithm and key id.
- Review the payload claims and the computed expiry status.
Frequently asked questions
Does this tool verify the JWT signature?
No. Verifying a signature requires the issuer secret or public key, and sending that to a web tool would be a serious security risk. This decoder inspects the header and payload only; always verify signatures server side in your application.
Is it safe to paste a production token here?
Decoding happens entirely in your browser and no token is transmitted or stored. That said, a valid JWT is a live credential, so treat it carefully and prefer expired or staging tokens wherever possible.
Why is my token payload unreadable?
You may have a JWE rather than a JWS. JWE tokens have five segments and an encrypted payload that cannot be decoded without the key, whereas a standard signed JWT has three segments and a Base64URL-encoded JSON payload.
Related tools
- Encoder & DecoderFree online URL encoder, Base64 encoder/decoder and HTML entity escaper. Encode and decode strings instantly and privately in your browser.
- JSON VisualizerExplore JSON as a collapsible tree. Navigate deeply nested API responses, inspect types and copy paths without scrolling through raw text.
- Code FormatterFree online code beautifier for JSON, SQL, XML, HTML and CSS. Format minified code into readable, indented output instantly and privately.
JWT Decoder is free to use with no account, no ads and no usage limits. Every calculation runs locally in your browser, so nothing you paste is ever uploaded. See our privacy policy.