JWT Decoder
Processed Client SideDecode and inspect JSON Web Token header, payload, and signature. Timestamps are shown in human-readable form.
Bookmark this tool now — skip the search next time you need it.
About JWT Decoder
This tool runs entirely in your browser. Whatever you paste is processed on your own device and is never uploaded, logged, or sent to any server.
Paste a JSON Web Token and immediately see what is inside it. A JWT is three Base64url segments separated by dots — a header describing the signing algorithm, a payload holding the claims, and a signature. This decoder splits the token, decodes the first two segments into readable JSON, and shows the signature separately without attempting to verify it. Standard time claims are translated from raw epoch numbers into human dates, and the token is checked against the current time so an expired token is flagged as expired rather than leaving you to do the arithmetic. It is the quickest way to answer "what user is this token for, what scopes does it carry, and has it already expired".
Key features
- Splits and decodes the header and payload of any JWT into formatted, colour-highlighted JSON
- Expiry check against the current time, with clear Expired or Active status
- Human-readable dates for the standard exp, iat, and nbf time claims instead of raw epoch seconds
- Header section shows the signing algorithm and token type, which is where you confirm the algorithm is what you expect
- Signature segment is displayed as-is and clearly marked as not verified
- Handles base64url encoding and missing padding, which is what breaks a generic Base64 decoder on JWTs
- Clear errors for tokens with the wrong number of segments or an undecodable payload
- Copy the decoded payload as JSON in one click
- Runs entirely in your browser — access tokens are never transmitted anywhere
How to use it
- Paste the full token — all three dot-separated segments — into the input pane.
- Click Decode.
- Read the header to see the algorithm, and the payload for the claims.
- Check the status badge for Expired or Active, and read the formatted exp and iat dates.
- Click Copy payload if you need the claims as JSON elsewhere.
Tips & common mistakes
- Decoding is not verification. Anyone can read a JWT and anyone can forge one that decodes cleanly — only checking the signature against the secret or public key on your server proves it is genuine.
- Because the payload is readable by anyone holding the token, never put passwords, card numbers, or anything private in it. Base64url is transport encoding, not protection.
- If the header says alg is none, treat the token as hostile. Accepting an unsigned token is a well-known authentication bypass.
- exp and iat are seconds since the epoch, while JavaScript Date works in milliseconds. Comparing them without multiplying by 1000 is the single most common JWT bug.
- A token that looks valid but is rejected by your API is often a clock problem — nbf and exp are evaluated against server time, so a few minutes of drift between machines will reject a fresh token.
- Three segments means a signed JWS, which is what this tool reads. A token with five segments is an encrypted JWE and its payload cannot be decoded without the key.
- To create a token from scratch rather than decode an existing one, use the JWT Builder.