Skip to content
ToolSuite

JWT Decoder

Decode a JSON Web Token and read its header and claims, with expiry checked.

Processed in your browser

Your result will appear here as soon as you add some input.

How to use it

  1. 1Paste your input into the input box, or type it directly.
  2. 2Adjust the options if you need something other than the defaults.
  3. 3The result updates as you type.
  4. 4Copy the result to your clipboard or download it as a file.

About the JWT Decoder

A JWT is three Base64URL segments separated by dots: a header describing the algorithm, a payload of claims, and a signature. The first two are encoded, not encrypted - anyone holding the token can read them.

Standard claims are explained as they are decoded, and `exp`, `nbf` and `iat` are converted from Unix seconds to readable dates so an expiry problem is immediately obvious.

Decoding is not verification. Checking the signature requires the signing key, and no signing key should ever be pasted into a web page - so this tool deliberately does not offer it. Treat a decoded token as an unverified claim.

Questions people ask

Is my token sent anywhere?

No. Decoding happens entirely in your browser. That said, an access token is a live credential - prefer a token from a test environment, and rotate anything you paste into any online tool.

Why does it not verify the signature?

Verification needs the secret or public key. Asking you to paste a signing secret into a web page would be bad advice regardless of how the page behaves, so the tool stops at decoding.

Is your code uploaded to a server?

No. This tool runs entirely in your browser using standard web APIs, so your code never leaves your device. You can confirm it by opening your browser's network panel while the tool runs, or by disconnecting from the internet after the page has loaded.

Is it free, and do I need an account?

Yes, it is free, and there is no account, no sign-up and no watermark on the result. The project is funded by optional donations.