JWT Decoder

Paste a JWT to see its decoded header and payload. Decoding only — this does not verify the signature.

JWT
Paste a JWT above to see its decoded contents.

What is the JWT Decoder?

A JWT (JSON Web Token) is a compact, three-part token used to carry claims — who a user is, what they're allowed to do, when the token expires — typically for authentication in REST APIs. This tool decodes the header and payload sections so you can read their contents directly, instead of eyeballing a wall of base64.

It decodes only — it does not and cannot verify the signature, since that requires the secret key or public key the token was signed with, which should never be pasted into a third-party tool.

How to use it

  1. Paste a JWT into the box — any token with the standard header.payload.signature format.
  2. The decoded header and payload appear instantly as formatted JSON.
  3. If the token has an exp (expiry) claim, a status banner shows whether it's expired.
  4. Use "Load sample" to see a working example first.

How it works

A JWT is three base64url-encoded segments joined by dots: header.payload.signature. This tool splits on the dots, base64url-decodes the first two segments, and parses each as JSON — the same process any JWT library performs before checking the signature.

The signature segment is displayed but never decoded or verified, since it's a cryptographic hash, not JSON — verifying it correctly would require the signing key.

Example

A decoded payload typically looks like:

{
"sub": "1234567890",
"name": "Ada Lovelace",
"iat": 1716000000,
"exp": 1800000000
}

Frequently asked questions

Does this verify that the JWT is valid/trustworthy?

No — it only decodes the readable parts. A token could be decoded perfectly here and still have an invalid signature. Never trust a JWT's contents without verifying its signature server-side with the correct key.

Is it safe to paste a real JWT here?

Decoding happens entirely in your browser and the token is never sent anywhere — but as a general habit, avoid pasting tokens from production systems into any third-party tool, including this one.

What do "iat" and "exp" mean?

"iat" (issued at) and "exp" (expiration) are standard JWT claims storing Unix timestamps — this tool converts exp into a readable date and flags whether it has passed.

Why does the header usually just say alg and typ?

The header identifies the signing algorithm (like HS256 or RS256) and token type (JWT) — it's intentionally minimal; the actual claims live in the payload.

Can I decode a token with a custom/non-standard payload?

Yes — any valid base64url-encoded JSON payload decodes correctly, standard claims or not.