Skip to main content
ToolsBay

Runs in your browser — nothing is uploaded · verify

JWT Decoder — free, and it runs in your browser

Decode a JSON Web Token to inspect its header, payload and expiry.

  • Read the header and payload of a JSON Web Token without a server round trip.
  • Expiry, issued-at and not-before are shown as real dates, not epoch numbers.
  • The token is decoded in the page, which matters because it is a live credential.
  • 70 tools

    Free, with no account and no watermark

  • 0 bytes

    Of your files or text uploaded — this tool runs in the tab

  • No queue

    The work happens in this tab, not in a line behind other users

Three steps, nothing to install

JWT Decoder in three steps

  1. JWT123456Paste it in — it never leaves the tab

    Paste the token

    Straight out of an Authorization header, a cookie or a log line. It stays in the page.

  2. JWTEvery field, broken out and checked

    Read the claims

    Header and payload are decoded and formatted, with the timestamp claims rendered as dates and the expiry checked against now.

  3. Copy CLAIMS

    Take what you need

    Copy a claim, or the decoded payload, into your debugging notes.

Why use JWT Decoder

  • Decoding is not verifying

    A JWT payload is Base64, not encryption — anyone holding the token can read it. The signature is what proves it is genuine, and checking that needs the secret. The page is explicit about the difference.

  • Expiry, in human time

    The whole reason you are looking at a token is usually to find out whether it has expired. The exp claim is converted and compared against now, rather than left as ten digits.

  • Your text stays in the page

    What you paste is not transmitted or stored, so an API response full of customer records, a token or an internal query never leaves your machine.

Frequently asked questions

No — verifying needs the right key: the shared secret for HS256, or the issuer’s public key for RS256 and ES256. Decoding only reads the header and payload, which are Base64url-encoded rather than encrypted. Verification must happen on your server, where the key lives.

What a JWT actually contains

A JSON Web Token is three Base64url segments joined by dots: a header naming the signing algorithm, a payload of claims, and a signature over the first two. Only the signature involves a key. The header and payload are plain encoded JSON that anyone can read.

This is the single most misunderstood thing about JWTs. Putting a user's email, role or internal ID in a token is fine — putting anything you would not print on a postcard is not. The signature guarantees integrity, not confidentiality.

Debugging with a decoder

Most JWT problems are one of three things: the token has expired, the claims are not what the issuer thinks they are, or the algorithm in the header does not match what the verifier expects. All three are visible without a key, which is what makes decoding a useful first step. The expiry check here compares exp against your device clock — if that clock is wrong, so is the verdict.

The segments are Base64url-encoded, so the Base64 decoder will read them individually. To convert the epoch timestamps by hand, use the Unix timestamp converter. To inspect the Authorization header a token arrived in, use the HTTP header parser.

Related guides

More tools

70 tools, none of which want your file

Everything this tool does happens in the page you are looking at. No account, no upload, no watermark.