freetools.guru

JWT Decoder

Decode JWT headers, payloads and standard claims instantly in your browser. Inspect the algorithm, token type, exp/iat/nbf timestamps and expiration status — with a clear warning that decoding is not signature verification. Private, no uploads.

JWTs are normally under a few hundred characters — the limit is 100,000.

Tip: press Ctrl + Enter to decode

JWT payloads are encoded, not encrypted. Anyone holding the token can read its header and payload without any key.

Your token is decoded locally in your browser and is not uploaded. This tool never sends your token, claims or signature anywhere, and no account is required.

Decoding is not signature verification — never treat a decodable token as authentic.

How it works

  1. 1Paste your JWT. Paste a compact JSON Web Token — three dot-separated segments: header.payload.signature.
  2. 2Decode the token. Click Decode JWT (or press Ctrl+Enter). The header and payload are decoded from Base64URL as UTF-8 and parsed as JSON entirely in your browser.
  3. 3Inspect header, payload and claims. Read the algorithm, token type, signature segment, and standard claims such as iss, sub, aud, exp, iat and nbf with UTC/local timestamps and expiration status.
  4. 4Copy or download. Copy the header, payload, signature, the full decoded JSON, or the token itself, and download a decoded-jwt.json file — all without leaving your browser.

Best practices

  • Remember that decoding is not verification — a token that decodes cleanly is not proof of authenticity, and this tool never verifies signatures.
  • JWT payloads are encoded, not encrypted: anyone holding the token can read its contents without any key.
  • Expiration (exp), not-before (nbf) and issued-at (iat) status uses your device clock and is a timestamp check only — never treat it as a signature check.
  • A token declaring alg=none is unsigned; treat it as untrusted regardless of how its claims read.
  • Never paste production tokens you are not allowed to inspect — even though this tool never uploads them, pasting tokens into any tool should be done with care.

Frequently Asked Questions

What does JWT Decoder do?
It decodes and inspects a JSON Web Token locally in your browser. You can read the header, the payload, the signature segment, and any standard claims such as issuer (iss), subject (sub), audience (aud), expiration (exp), issued-at (iat) and not-before (nbf), plus their status against your device clock.
Does decoding verify a JWT signature?
No. This tool decodes and inspects the token only. Signature verification requires the appropriate trusted key and is a separate security operation. Anyone can create a token with readable header and payload values, so a decodable token is never proof of authenticity.
Can anyone read a JWT payload?
Yes. JWT payloads are encoded, not encrypted. Anyone who holds the token can decode and read its header and payload without any key, so never place passwords, secrets or personal data in a JWT.
What is the exp claim?
exp (Expiration Time) is the timestamp after which the token should no longer be accepted. This tool compares it with your device clock and shows whether it has passed, but that is a timestamp check only — it does not verify the signature.
What is the iat claim?
iat (Issued At) is the timestamp when the token was issued. The tool shows it in UTC and local time and tells you how long ago it was issued. A future iat triggers a warning but is not treated as cryptographic invalidity.
What is the nbf claim?
nbf (Not Before) is the earliest time at which the token should be accepted. The tool shows whether the token is active according to nbf using your device clock, again as a timestamp check only.
What does alg mean?
alg is the header claim that names the signing algorithm the token claims to use, such as HS256, RS256, ES256 or EdDSA. The tool labels known algorithms for display only — it never verifies that the signature actually matches the algorithm.
What does alg=none mean?
alg=none declares that the token is unsigned. The tool still decodes it but shows a prominent warning that anyone can craft such a token, and that no signature exists to verify.
Does this tool send my JWT to a server?
No. Your token is decoded locally in your browser and is never uploaded anywhere. This tool makes no network requests and requires no account.

Related Tools

Supported tokens

Decode standard compact JWTs — three dot-separated Base64URL segments (header.payload.signature) — directly in your browser. Headers and payloads are decoded as UTF-8 and must parse as JSON objects. Base64URL is fully supported (- and _ characters plus missing padding), and standard claims (iss, sub, aud, exp, nbf, iat, jti) are summarised with UTC and local timestamps. Up to 100,000 characters per token are supported. No signature verification is performed.

Privacy & data removal

Your token is decoded entirely in your browser and is never uploaded to any server. No account is required to use the JWT Decoder, and we never store or share your tokens, claims or signatures.