JWT Decoder
Decode and inspect JWT (JSON Web Token) header, payload, and signature instantly. Free, browser-based, no token sent to servers.
- Runs in your browser
- Your data never leaves your browser
- Free · No Sign-Up
Scan with WeChat to share this tool
Examples, details and FAQ Worked examples, how it compares with other tools, and answers to common questions.
Examples
The example token. Load Example fills in an HS256 token. The tool shows the header {"alg":"HS256","typ":"JWT"} and this payload:
{
"sub": "1234567890",
"name": "John Doe",
"iat": 1516239022,
"exp": 1893456000
}
Next to iat it prints Thu, 18 Jan 2018 01:30:22 GMT, and next to exp it prints Tue, 01 Jan 2030 00:00:00 GMT — valid. The dates are in UTC; “valid” or “EXPIRED” compares exp with your computer’s clock and nothing else.
Non-ASCII claims. The payload segment eyJuYW1lIjoiSm9zw6kiLCJyb2xlcyI6WyJhZG1pbiJdfQ decodes to {"name":"José","roles":["admin"]}. JSON in a JWT is UTF-8 (RFC 7519 §7.1), so the decoder turns the Base64URL bytes into UTF-8 text before parsing. A decoder that only calls atob() shows José instead.
To decode a single segment without the token structure, paste it into Base64 Encode / Decode with URL-safe selected. To build a test token with your own claims and secret, use the JWT Generator.
What the Decoder Checks
- The input must have exactly three parts separated by dots. Otherwise the status shows a message such as
Invalid JWT: expected 3 dot-separated parts, got 5.for five parts. An encrypted JWE has five parts and cannot be read without the key (RFC 7516 §3). - Header and payload must be Base64URL. Missing
=padding and the standard+and/characters are accepted. A quote copied from a JSON response, as in“eyJhbGciOiJub25lIn0.e30.”, or aBearerprefix givesFailed to Base64URL-decode token parts.Paste the token alone. - A segment that decodes but is not JSON is shown as “(unable to parse)”.
- The signature is displayed as the raw Base64URL string and is not verified. A token with a forged payload looks exactly the same here as a genuine one. Never accept a token on the server because it decodes; verify the signature with the issuer’s key, and check
exp,nbf,issandaudas RFC 8725 §3 recommends.
Limits
- Line breaks inside the token, and spaces or tabs next to them, are ignored, so a token wrapped in a log or an e-mail decodes as one piece (the status shows
Decoded successfully.). Any other space or tab inside the header or payload gives the decode error. - Only
exp,iatandnbfwith numeric values in seconds get a readable UTC date. The original numeric precision is retained; the date note displays whole seconds. A millisecond value, which some libraries write by mistake, shows a date tens of thousands of years ahead. - The “valid” and “EXPIRED” labels and the signature note are in English on every language version of the page.
- Tokens are not saved anywhere, and this page loads no analytics or ad scripts, because JWTs often carry session credentials.
What is a JWT?
A JSON Web Token (JWT) is a compact, URL-safe token format used for authentication and information exchange. It consists of three Base64URL-encoded parts separated by dots:
- Header: Specifies the signing algorithm (e.g., HS256, RS256) and token type.
- Payload: Contains claims — statements about an entity (typically the user) and additional metadata.
- Signature: Ensures the token has not been tampered with. Requires the secret or public key to verify.
Common claims include sub (subject), iss (issuer), exp (expiration),
iat (issued at), and aud (audience).
FAQ
Is my JWT token sent to any server?
No. Decoding happens in your browser using JavaScript. The token is not sent to any server or written to browser storage, and this page does not load Google Analytics or AdSense.
Can this tool verify the JWT signature?
Signature verification requires the secret key or public key. This tool decodes and displays the payload without verifying the signature — use it to inspect claims only.
What are the three parts of a JWT?
A JWT is three Base64URL-encoded parts separated by dots: Header (algorithm and token type), Payload (claims/data), and Signature (used to verify integrity).
What does 'exp' mean in the payload?
'exp' is the expiration time claim — a Unix timestamp in seconds indicating when the token expires. This tool shows a human-readable date next to the raw value and marks it valid or EXPIRED by your device clock.
Why are the dates shown in GMT instead of my time zone?
The date notes are always UTC (written as GMT), whatever time zone your device uses. Add your offset to read them: Thu, 18 Jan 2018 01:30:22 GMT is 20:30:22 on 17 January in New York (UTC−5). The valid or EXPIRED mark compares the raw seconds with your clock, so it does not depend on the time zone.