Converters
Calculators
Other Tools
Browse tools
Checkers

JWT decoder

Paste a JSON Web Token to see its header and payload, pretty-printed and readable. Decoding only — it does not verify the signature.

Never leaves your device No signup Free forever Not stored, not logged

JWT

header.payload.signature
Header
Payload
More checkers

Related tools you might need next

All checkers

How it works

Two steps, no account

1

Paste your token

A JWT is three Base64URL-encoded segments separated by dots — header, payload, and signature.

2

Read the decoded claims

The header and payload are decoded and pretty-printed instantly. If the payload has an exp claim, its expiry status is shown too.

FAQ

Common questions

Does this verify the token's signature?
No. Verifying a signature requires the secret (for HMAC algorithms) or the public key (for RSA/ECDSA algorithms) that issued the token — neither is ever available to a browser-only tool, and this one never asks for it. This decoder only shows you what's inside the token; it does not confirm the token is genuine or untampered.
Why is JWT decoding not the same as Base64 decoding?
JWTs use Base64URL encoding, a variant that replaces + and / with - and _ and drops the trailing = padding so tokens are safe inside URLs and headers. Standard Base64 decoders choke on that without a translation step, which this tool handles automatically.
What does the expiry status mean?
If the payload includes an exp claim (a Unix timestamp in seconds), it's converted to a readable date and compared against your device's current time to show whether the token has already expired or is still valid, and by how much.
Is my token sent anywhere?
No. Splitting and decoding both happen entirely in your browser — nothing is transmitted, logged, or stored. That matters here more than most tools, since JWTs often carry session or identity claims.
ad slot · bottom of content 336×280 / responsive
Related

People who used this also used

JWT Decoder

Our JWT Decoder splits a JSON Web Token into its three parts and decodes the header and payload back into readable, formatted JSON. Paste a token and see exactly what claims it carries — including a plain-English read on whether it's expired — entirely in your browser.

How to Use the JWT Decoder

1. Paste Your Token

  • Copy a JWT (three dot-separated segments) into the input box
  • The tool splits it into header, payload, and signature automatically
  • Malformed tokens are flagged clearly instead of producing a blank or broken result

2. Read the Decoded Claims

  • The header (algorithm and token type) is pretty-printed on the left
  • The payload (the actual claims — subject, issuer, custom fields, etc.) is pretty-printed below it
  • Both are formatted with indentation so nested objects are easy to scan

3. Check Expiry, If Present

  • If the payload has an exp claim, its expiry is converted to a readable date
  • You'll see either "Valid until…" or "Expired … ago" based on your device's current time

Key Features

Correct Base64URL Decoding

  • JWTs use base64url encoding, not standard base64 — - and _ instead of + and /, and no = padding
  • This tool implements a proper base64url decoder rather than assuming plain atob() will work, which it won't for most real-world tokens

Formatted Output

  • Header and payload are shown as indented, readable JSON, not a single dense line
  • Each has its own copy button

Expiry Awareness

  • Automatically detects the standard exp claim (a Unix timestamp in seconds)
  • Converts it to a local date/time and a human phrase like "in 3 days" or "3 days ago"

Clear Error Handling

  • Wrong number of segments, invalid base64url, or invalid JSON are each reported with a specific message
  • No uncaught errors or blank screens on malformed input

Use Cases

1. API Debugging

  • Quickly inspect what claims an access token or ID token actually contains
  • Confirm a token includes the scopes, roles, or user ID your backend expects

2. Authentication Development

  • Verify an auth provider is issuing tokens with the fields your app relies on
  • Check token expiry during login-flow debugging without writing a decode script

3. Learning JWTs

  • See the structure of a real token broken into its three parts
  • Understand what's actually inside a token before deciding how much to trust it

Technical Features

  • UTF-8 Aware: Payload text is decoded as UTF-8, so non-ASCII claim values display correctly
  • Real-Time Processing: Decoding happens as soon as you paste, no button required
  • No Network Calls: Nothing about your token is ever transmitted
  • Copy Integration: One-click copy for both the header and payload JSON

Why Use Our JWT Decoder

1. Decoding, Not Verification — Stated Plainly

  • This tool reads and displays what's inside a token
  • It never claims or implies the signature is valid, because a browser-only tool has no access to the secret or public key needed to check that

2. Correct Encoding Handling

  • Many "quick" decoders reuse plain atob() and silently fail on real tokens because of the base64url character substitutions and missing padding — this one handles that correctly

3. Privacy Focused

  • All decoding happens client-side
  • Nothing is logged or stored, which matters since JWTs often carry session or identity data

Understanding JSON Web Tokens

What Is a JWT?

A JSON Web Token (JWT) is a compact, URL-safe way to represent claims between two parties. It consists of three base64url-encoded segments separated by dots: a header describing the signing algorithm, a payload of claims, and a signature that lets the issuer's system verify the token wasn't tampered with.

The Three Segments

  1. Header: Typically specifies the algorithm (alg, e.g. HS256 or RS256) and token type (typ: JWT)
  2. Payload: The actual claims — standard ones like sub (subject), iat (issued at), exp (expiry), plus any custom fields the issuer adds
  3. Signature: A cryptographic signature over the header and payload, verifiable only with the issuer's secret or public key

Why Verification Needs a Key

The signature exists specifically so that a token can't be forged or altered without detection — but checking it requires the same secret (HMAC algorithms like HS256) or the issuer's public key (asymmetric algorithms like RS256) that created it. Neither is something a public, client-side decoding tool can ever legitimately have access to, which is why this tool sticks to decoding and display only.

Best Practices

  1. Never trust an unverified token server-side: Decoding shows you the claims, but only your backend, holding the correct key, can confirm the token is genuine
  2. Check expiry before relying on a token: An expired token should be rejected regardless of what its claims say
  3. Don't put sensitive data in the payload: JWT payloads are readable by anyone who has the token — they're encoded, not encrypted

Remember: this tool decodes and displays a JWT's contents for inspection and debugging — it does not and cannot verify the token's signature.