Skip to content

JWT Decoder

Read a JWT's header and claims without sending it anywhere.

  • 100% Free
  • No Sign Up
  • Works in Your Browser

How to use the JWT decoder

Three steps, all in your browser.

  1. 1

    Paste your input

    Type or paste your code or data. Press Sample to try an example.

  2. 2

    Choose the direction

    Encode or decode. Errors point at what's wrong with the input.

  3. 3

    Copy the result

    Copy the output in one click. Nothing is saved or sent anywhere.

JWT Decoder: what to know

The JWT decoder splits a JSON Web Token into its parts and shows the header and payload as formatted JSON. A JWT (RFC 7519) is three Base64url-encoded segments separated by dots: a header naming the signing algorithm, a payload of claims, and a signature. Time claims such as exp (expires), iat (issued at) and nbf (not before) are Unix timestamps, shown here as readable dates.

Decoding is not verification. The header and payload are only encoded, not encrypted, so anyone holding a token can read them, and anyone can create a token with any claims they like. What makes a JWT trustworthy is the signature, which your server must check with the secret (HS256) or the issuer's public key (RS256, ES256) before using any claim. This page can check HS256, HS384 and HS512 signatures if you enter the shared secret; tokens signed with RS256 or ES256 need the issuer's public key. Never put secrets in a JWT payload.

The token is decoded entirely in your browser and is not sent to our server. A live token still works as a credential until it expires, so treat it like a password: avoid pasting production tokens into tools you don't trust, and don't share screenshots of them.

Popular uses

  • Checking which claims and scopes an access token carries
  • Finding out when a token expires
  • Debugging authentication errors in an API
  • Inspecting ID tokens from OAuth and OpenID Connect providers

Tips for the best result

  • A 401 with a token that looks fine is often an expired exp or an aud (audience) meant for another API.
  • An alg of none in the header means an unsigned token; servers must reject it.
  • Check exp against the current time in UTC: the timestamp converter helps.

Read how JustYourDev works and our privacy details. Code, data and files you use here are processed in your browser and are never sent to our server.

Frequently asked questions