JWT Decoder
Our JWT Decoder splits a JSON Web Token into its three parts and decodes the header and payload back into readable, formatted JSON. Paste a token and see exactly what claims it carries — including a plain-English read on whether it's expired — entirely in your browser.
How to Use the JWT Decoder
1. Paste Your Token
- Copy a JWT (three dot-separated segments) into the input box
- The tool splits it into header, payload, and signature automatically
- Malformed tokens are flagged clearly instead of producing a blank or broken result
2. Read the Decoded Claims
- The header (algorithm and token type) is pretty-printed on the left
- The payload (the actual claims — subject, issuer, custom fields, etc.) is pretty-printed below it
- Both are formatted with indentation so nested objects are easy to scan
3. Check Expiry, If Present
- If the payload has an
expclaim, its expiry is converted to a readable date - You'll see either "Valid until…" or "Expired … ago" based on your device's current time
Key Features
Correct Base64URL Decoding
- JWTs use base64url encoding, not standard base64 —
-and_instead of+and/, and no=padding - This tool implements a proper base64url decoder rather than assuming plain
atob()will work, which it won't for most real-world tokens
Formatted Output
- Header and payload are shown as indented, readable JSON, not a single dense line
- Each has its own copy button
Expiry Awareness
- Automatically detects the standard
expclaim (a Unix timestamp in seconds) - Converts it to a local date/time and a human phrase like "in 3 days" or "3 days ago"
Clear Error Handling
- Wrong number of segments, invalid base64url, or invalid JSON are each reported with a specific message
- No uncaught errors or blank screens on malformed input
Use Cases
1. API Debugging
- Quickly inspect what claims an access token or ID token actually contains
- Confirm a token includes the scopes, roles, or user ID your backend expects
2. Authentication Development
- Verify an auth provider is issuing tokens with the fields your app relies on
- Check token expiry during login-flow debugging without writing a decode script
3. Learning JWTs
- See the structure of a real token broken into its three parts
- Understand what's actually inside a token before deciding how much to trust it
Technical Features
- UTF-8 Aware: Payload text is decoded as UTF-8, so non-ASCII claim values display correctly
- Real-Time Processing: Decoding happens as soon as you paste, no button required
- No Network Calls: Nothing about your token is ever transmitted
- Copy Integration: One-click copy for both the header and payload JSON
Why Use Our JWT Decoder
1. Decoding, Not Verification — Stated Plainly
- This tool reads and displays what's inside a token
- It never claims or implies the signature is valid, because a browser-only tool has no access to the secret or public key needed to check that
2. Correct Encoding Handling
- Many "quick" decoders reuse plain
atob()and silently fail on real tokens because of the base64url character substitutions and missing padding — this one handles that correctly
3. Privacy Focused
- All decoding happens client-side
- Nothing is logged or stored, which matters since JWTs often carry session or identity data
Understanding JSON Web Tokens
What Is a JWT?
A JSON Web Token (JWT) is a compact, URL-safe way to represent claims between two parties. It consists of three base64url-encoded segments separated by dots: a header describing the signing algorithm, a payload of claims, and a signature that lets the issuer's system verify the token wasn't tampered with.
The Three Segments
- Header: Typically specifies the algorithm (
alg, e.g.HS256orRS256) and token type (typ: JWT) - Payload: The actual claims — standard ones like
sub(subject),iat(issued at),exp(expiry), plus any custom fields the issuer adds - Signature: A cryptographic signature over the header and payload, verifiable only with the issuer's secret or public key
Why Verification Needs a Key
The signature exists specifically so that a token can't be forged or altered without detection — but checking it requires the same secret (HMAC algorithms like HS256) or the issuer's public key (asymmetric algorithms like RS256) that created it. Neither is something a public, client-side decoding tool can ever legitimately have access to, which is why this tool sticks to decoding and display only.
Best Practices
- Never trust an unverified token server-side: Decoding shows you the claims, but only your backend, holding the correct key, can confirm the token is genuine
- Check expiry before relying on a token: An expired token should be rejected regardless of what its claims say
- Don't put sensitive data in the payload: JWT payloads are readable by anyone who has the token — they're encoded, not encrypted
Remember: this tool decodes and displays a JWT's contents for inspection and debugging — it does not and cannot verify the token's signature.