100 DevTools Hub
Encoders

JWT Decoder

Decode and inspect JSON Web Token (JWT) headers, claims, and payload data instantly inside your browser.

Free toolBrowser-basedNo sign-up

Tool workspace

Use JWT Decoder

Runs in your browser

Privacy-first processing

This tool is designed to process its working input in your browser. For details about site-level analytics, advertising, and data handling, see the Privacy Policy.

Signature is not verified

This tool only decodes the Base64URL header and payload and interprets selected time claims. A decoded JWT must not be treated as authentic or trusted until its signature and claims are verified by the receiving application.

Quick start

How to use JWT Decoder

  1. 1

    Paste your encoded JSON Web Token (JWT) string into the input text area.

  2. 2

    Paste a three-part compact signed JWT; the tool decodes the Base64URL-encoded Header and Payload JSON structures in real time.

  3. 3

    Inspect decoded claim properties, user details, scopes, and expiration timestamps.

  4. 4

    Click the "Copy" buttons to easily copy the decoded Header or Payload JSON directly to your clipboard.

Overview

About JWT Decoder

JSON Web Token (JWT), defined by RFC 7519, is a compact URL-safe format for representing claims between parties. JWTs can be carried inside signed JWS structures, encrypted JWE structures, or in limited cases be unsecured. They are widely used in authentication and authorization systems, but the format itself does not guarantee confidentiality or validity. A common signed JWT carried as a compact JWS has three dot-separated parts: Header, Payload, and Signature. The Header specifies metadata such as the signing algorithm and token type, while the Payload contains claims such as subject, issue time (iat), and expiration time (exp). The header and payload are Base64URL-encoded and can be decoded by anyone who has the token. Encrypted compact JWE structures use five parts instead. A signature can protect integrity only when it is actually verified, and decoding alone does not prove that a token should be trusted. Our JWT Decoder helps developers inspect token structure, header values, claims, and time-based fields in the browser. It can show whether an exp timestamp is already in the past, but that is not the same as validating a token. The decoder does not verify cryptographic signatures or authorization rules. Use test or redacted tokens whenever possible, especially because production JWTs may function as bearer credentials.

FAQ

Frequently asked questions

Is it safe to paste sensitive production JWTs into this tool?
The decoder performs its parsing in your browser, but production JWTs can be sensitive bearer credentials. Prefer test or redacted tokens whenever possible and follow your organization’s security policy before pasting live credentials into any web page.
Can this tool verify the digital signature of a JWT?
No. This utility decodes the header and payload only. Signature verification requires the correct verification material for the token’s algorithm, such as a shared secret for HMAC or a public key for asymmetric signatures, plus checks for issuer, audience, time claims, and application policy.
Why can anyone decode a JWT if it is used for security?
Many JWTs are signed JWS tokens, where the encoded claims remain readable and integrity depends on signature verification. JWTs can also be encrypted with JWE, and RFC 7519 also defines unsecured JWTs. Base64URL encoding alone provides no confidentiality, so sensitive plaintext should not be placed in an unencrypted token.
What do standard JWT claims like sub, iat, and exp mean?
Standard registered claims include "sub" (Subject/User ID), "iat" (Issued At Unix timestamp), "exp" (Expiration Unix timestamp), "iss" (Issuer authority), and "aud" (Audience target).