Strinza

JSON Web Token (JWT) Decoder

Decode JWT headers, payload claims, and token expiration status 100% locally in your browser.

JSON Web Token (JWT) Structure & Claims Reference

JSON Web Tokens are an open, industry-standard RFC 7519 method for representing claims securely between two parties.

1. Three Token Components

JWTs consist of three dot-separated Base64URL parts: Header.Payload.Signature.

2. Expiration Verification

Inspect registered claims like exp (expiration time) and iat (issued at).

3. Privacy Protection

Decoding runs 100% in client JavaScript. Sensitive auth tokens are never logged or stored on any server.

About the JWT Decoder

The JWT Decoder splits a JSON Web Token into its three Base64URL segments and pretty-prints the header and payload. It resolves the numeric exp, iat and nbf timestamps into readable dates and flags whether the token has already expired, which is usually the fastest way to explain an unexpected 401 from an API. The signature segment is displayed but not verified, because verification requires the issuer secret or public key.

How to use the JWT Decoder

  1. Paste the JWT, with or without the "Bearer " prefix, into the input field.
  2. Read the decoded header to confirm the signing algorithm and key id.
  3. Review the payload claims and the computed expiry status.

Frequently asked questions

Does this tool verify the JWT signature?

No. Verifying a signature requires the issuer secret or public key, and sending that to a web tool would be a serious security risk. This decoder inspects the header and payload only; always verify signatures server side in your application.

Is it safe to paste a production token here?

Decoding happens entirely in your browser and no token is transmitted or stored. That said, a valid JWT is a live credential, so treat it carefully and prefer expired or staging tokens wherever possible.

Why is my token payload unreadable?

You may have a JWE rather than a JWS. JWE tokens have five segments and an encrypted payload that cannot be decoded without the key, whereas a standard signed JWT has three segments and a Base64URL-encoded JSON payload.

JWT Decoder is free to use with no account, no ads and no usage limits. Every calculation runs locally in your browser, so nothing you paste is ever uploaded. See our privacy policy.