JWT Decoder
Decode JWT headers, payloads and standard claims instantly in your browser. Inspect the algorithm, token type, exp/iat/nbf timestamps and expiration status — with a clear warning that decoding is not signature verification. Private, no uploads.
JWTs are normally under a few hundred characters — the limit is 100,000.
JWT payloads are encoded, not encrypted. Anyone holding the token can read its header and payload without any key.
Your token is decoded locally in your browser and is not uploaded. This tool never sends your token, claims or signature anywhere, and no account is required.
Decoding is not signature verification — never treat a decodable token as authentic.
How it works
- 1Paste your JWT. Paste a compact JSON Web Token — three dot-separated segments: header.payload.signature.
- 2Decode the token. Click Decode JWT (or press Ctrl+Enter). The header and payload are decoded from Base64URL as UTF-8 and parsed as JSON entirely in your browser.
- 3Inspect header, payload and claims. Read the algorithm, token type, signature segment, and standard claims such as iss, sub, aud, exp, iat and nbf with UTC/local timestamps and expiration status.
- 4Copy or download. Copy the header, payload, signature, the full decoded JSON, or the token itself, and download a decoded-jwt.json file — all without leaving your browser.
Best practices
- Remember that decoding is not verification — a token that decodes cleanly is not proof of authenticity, and this tool never verifies signatures.
- JWT payloads are encoded, not encrypted: anyone holding the token can read its contents without any key.
- Expiration (exp), not-before (nbf) and issued-at (iat) status uses your device clock and is a timestamp check only — never treat it as a signature check.
- A token declaring alg=none is unsigned; treat it as untrusted regardless of how its claims read.
- Never paste production tokens you are not allowed to inspect — even though this tool never uploads them, pasting tokens into any tool should be done with care.
Frequently Asked Questions
What does JWT Decoder do?
Does decoding verify a JWT signature?
Can anyone read a JWT payload?
What is the exp claim?
What is the iat claim?
What is the nbf claim?
What does alg mean?
What does alg=none mean?
Does this tool send my JWT to a server?
Related Tools
Supported tokens
Decode standard compact JWTs — three dot-separated Base64URL segments (header.payload.signature) — directly in your browser. Headers and payloads are decoded as UTF-8 and must parse as JSON objects. Base64URL is fully supported (- and _ characters plus missing padding), and standard claims (iss, sub, aud, exp, nbf, iat, jti) are summarised with UTC and local timestamps. Up to 100,000 characters per token are supported. No signature verification is performed.
Privacy & data removal
Your token is decoded entirely in your browser and is never uploaded to any server. No account is required to use the JWT Decoder, and we never store or share your tokens, claims or signatures.
