JWT Decoder

Decode a JSON Web Token's header and payload without a server.

About this tool

Paste a JSON Web Token to decode its header and payload into readable, formatted JSON. Decoding happens entirely in your browser — the token is never sent anywhere. This tool does not verify the signature, so a token decoding cleanly is not proof it is authentic or unaltered.

What a JWT is. Three Base64url-encoded strings joined by dots: header.payload.signature.

  • Header — a small JSON object naming the signing algorithm (alg, e.g. HS256, RS256) and token type (typ: "JWT").
  • Payload — a JSON object of claims: who the token is about (sub), who issued it (iss), who it's for (aud), when it was issued (iat) and expires (exp), plus any application data.
  • Signature — a MAC or digital signature over the first two parts, using a secret (HS*) or private key (RS*/ES*). It's what makes the token tamper-evident.

The header and payload are not encrypted. Base64url is an encoding, not encryption — anyone holding the token can read every claim, exactly as this tool does. Never put a password, a full card number, or any secret in a JWT payload. If the contents must be hidden, that's JWE (encrypted tokens), which is a different format.

Timestamps. iat, exp, and nbf are Unix timestamps in seconds (not milliseconds). An exp in the past means the token is expired — though only the server enforces that. To read one, drop it into the Unix timestamp converter.

Decoding vs. verifying. This tool decodes. Verifying — confirming the signature matches, the token isn't expired, and the issuer and audience are right — needs the signing key and must happen server-side. A decoded token tells you what a token claims; only verification tells you whether to believe it. A classic attack swaps alg to none or downgrades RS256 to HS256; a decoder shows the change, a correct verifier rejects it.

Handle real tokens carefully. Decoding is local and nothing is transmitted, but a valid token is a live credential until it expires. Avoid pasting production tokens with sensitive claims into any tool you don't control, and don't commit them to code or paste them in tickets.

The payload is JSON — the JSON formatter and the JSON guide cover its grammar. The parts are Base64url; the encoding guide explains that variant.

Frequently asked questions

Does this verify the token is valid or authentic?
No. Verifying a signature needs the secret or public key used to sign it, which this tool never has. It only decodes the readable header and payload.
Why are there three parts separated by dots?
Base64url-encoded header, payload, and signature. The header names the algorithm, the payload holds the claims, and the signature makes the first two tamper-evident.
Is the payload encrypted?
No. It's only Base64url-encoded, so anyone with the token can read it. Never store secrets in a JWT payload.
The token has an "exp" — is it expired?
exp is a Unix timestamp in seconds. If it's in the past the token is expired, but enforcement is the server's job, not the client's.
Is it safe to paste a real token here?
Decoding is local and nothing is sent, but treat any token as a credential. Don't paste production tokens with sensitive claims into tools you don't control.
My token won't decode — what's wrong?
Usually a copy-paste error: a missing part, extra whitespace or a line break inside it, or a leading Bearer prefix that needs removing. A JWT is exactly three dot-separated Base64url chunks.