JWT Decoder

Works fully offline Developer

Paste a JWT to see its header and payload as readable JSON, without needing the signing secret or a running application to log in to.

0 characters

Overview

A JWT's header and payload are just Base64-encoded JSON, not encrypted — anyone with the token can already read the claims inside it, which is exactly what this tool does for you. That makes it useful for debugging auth flows, checking token expiry, or confirming what claims an issuer actually included, without needing to verify the signature or have access to the signing key. When you do need to confirm a token is genuine, paste the secret or public key to verify its signature, still without anything leaving your browser.

Examples & Sample Data

Sample token

Input
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
Output
Header: {"alg":"HS256","typ":"JWT"}
Payload: {"sub":"1234567890","name":"John Doe","iat":1516239022}
iat → 18 Jan 2018, 01:30:22 UTC
Verified with the secret "your-256-bit-secret"

How It Works

  1. Paste a JWT into the input box. The header and payload decode as you type.
  2. Check the status line to see whether the token has expired, isn't valid yet, or has no expiry at all.
  3. Read the registered claims table for issuer, subject, audience, and exp/iat/nbf times as real dates.
  4. To verify the signature, paste the shared secret (HS256/384/512) or the issuer's public key as a PEM or JWK/JWKS (RS, PS, ES, EdDSA), then click Verify signature.

Tips & Best Practices

  • Never accept a token whose header says "alg": "none". It has no signature, so anyone could have written it.

Frequently Asked Questions

No. The token is decoded entirely in your browser — it never leaves your device, which matters since a JWT can contain sensitive claims.

Yes, if you provide the key. Paste the shared secret for HS256/384/512, or the public key as a PEM or JWK for RS256/384/512, PS256/384/512, ES256/384/512, and EdDSA. With a JWKS, the key matching the token's kid is used. Decoding alone never verifies anything.

Since decoding happens locally and nothing is transmitted, it's safe from a network standpoint — but treat any token as sensitive and avoid sharing screenshots of the decoded output.

They're Unix timestamps in seconds: exp is when the token expires, iat is when it was issued, and nbf is when it becomes valid. The claims table shows each as a local date and time with how long ago or how soon it is.

A five-part token is an encrypted JWT (JWE). Its payload is ciphertext, so it can only be read with the decryption key. Signed JWTs (JWS) have three parts and their payload is readable by anyone.

Related Tools

Explore more high-performance utilities.