JWT Decoder
Read a JWT's header and claims without sending it anywhere.
- 100% Free
- No Sign Up
- Works in Your Browser
JWT decoder
Decode a JSON Web Token
More Developer Tools
View all tools- Base64 encode/decodeEncode and decode Base64 text
- Image to Base64Turn an image into a data URI
- URL encode/decodePercent-encode and decode URLs
- HTML entity encoderEscape and unescape HTML entities
- JSON escape/unescapeEscape text for a JSON string
- JSON formatterPretty-print and indent JSON
- UUID generatorGenerate random v4 or time-ordered v7 UUIDs
- Timestamp converterConvert Unix epoch time to dates
- Regex testerTest regular expressions live
Every everyday developer tool, right in your browser.
No installs. No uploads. No signup.
Browse all 36 tools- Developer tools
- 36
- Cheat sheets
- 10
- Bytes uploaded
- 0
How to use the JWT decoder
Three steps, all in your browser.
- 1
Paste your input
Type or paste your code or data. Press Sample to try an example.
- 2
Choose the direction
Encode or decode. Errors point at what's wrong with the input.
- 3
Copy the result
Copy the output in one click. Nothing is saved or sent anywhere.
JWT Decoder: what to know
The JWT decoder splits a JSON Web Token into its parts and shows the header and payload as formatted JSON. A JWT (RFC 7519) is three Base64url-encoded segments separated by dots: a header naming the signing algorithm, a payload of claims, and a signature. Time claims such as exp (expires), iat (issued at) and nbf (not before) are Unix timestamps, shown here as readable dates.
Decoding is not verification. The header and payload are only encoded, not encrypted, so anyone holding a token can read them, and anyone can create a token with any claims they like. What makes a JWT trustworthy is the signature, which your server must check with the secret (HS256) or the issuer's public key (RS256, ES256) before using any claim. This page can check HS256, HS384 and HS512 signatures if you enter the shared secret; tokens signed with RS256 or ES256 need the issuer's public key. Never put secrets in a JWT payload.
The token is decoded entirely in your browser and is not sent to our server. A live token still works as a credential until it expires, so treat it like a password: avoid pasting production tokens into tools you don't trust, and don't share screenshots of them.
Popular uses
- Checking which claims and scopes an access token carries
- Finding out when a token expires
- Debugging authentication errors in an API
- Inspecting ID tokens from OAuth and OpenID Connect providers
Tips for the best result
- A 401 with a token that looks fine is often an expired exp or an aud (audience) meant for another API.
- An alg of none in the header means an unsigned token; servers must reject it.
- Check exp against the current time in UTC: the timestamp converter helps.
Read how JustYourDev works and our privacy details. Code, data and files you use here are processed in your browser and are never sent to our server.