JWT Decoder

Paste a JSON Web Token (JWT) to decode its header, payload, and signature claims.

Header: Algorithm & Token TypeSegment 1
Awaiting token input...
Payload: Data ClaimsSegment 2
Awaiting token input...

About the JWT Decoder

Decode a JSON Web Token to inspect its header, payload claims and signature without sending it anywhere. JWTs are used for authentication and authorisation in web APIs, and being able to read the issuer, subject, audience, issued-at and expiry claims makes debugging login problems much faster. The decoder also tells you whether the token has expired based on the exp claim.

How to use the JWT Decoder

  1. Paste the full token (three dot-separated Base64url parts).
  2. Read the decoded header and payload as formatted JSON.
  3. Check the expiry status and timestamps.
  4. Copy any claim you need.

Frequently asked questions

Is it safe to paste my token here?

Decoding happens entirely in your browser and nothing is transmitted. Still, treat production tokens as secrets and avoid sharing them.

Does decoding verify the signature?

No. Verification requires the signing secret or public key. This tool only decodes the content so you can read it.

Why can anyone read my token's payload?

JWT payloads are Base64url-encoded, not encrypted. Never put sensitive data in a JWT unless you also encrypt it (JWE).