🎫

JWT Decoder

Paste a JWT to decode its Header and Payload, list standard claims and show expiry status.
JWT 📂 Developer 👤 ToolWorld 🏷️ v1.1.12
Loading...

JWT Decoder

Decode Header & Payload · Expiry hints · No signature verification

Header
—
Payload
—
Standard claims Recognised registered claims
ClaimValueNote
Signature Not verified
—

How to Use

📖 Tool Introduction


The JWT Decoder is a free online tool that helps developers read what is inside a JSON Web Token in seconds. In backend-for-frontend architectures, single sign-on flows and open-platform authorisation, you often end up holding a long string that looks like xxxxx.yyyyy.zzzzz, and that string is a JSON Web Token. Although it is unreadable to the naked eye, its Header and Payload segments are simply JSON documents encoded with base64url, which anyone can decode directly; only the third segment, the signature, is meant to remain protected. This tool brings pasting, decoding, pretty-printing and claim reference together on a single page. You paste the token into the input box, click decode, and the left pane renders the formatted Header in a dark code block while the right pane renders the Payload. Below them, a table lists the registered claims iss, sub, aud, exp, iat, nbf and jti one by one, and every Unix timestamp is automatically converted into a human-readable local date and time. The most practical part is the expiry banner: using your device clock it tells you whether the token is still valid, how long remains, or whether it has already expired, so you never have to do timestamp arithmetic by hand while debugging an API. It is important to understand that this tool only decodes and displays; it does not and should not replace server-side signature verification, which is why the page always marks the signature as unverified, so you never mistake reading the content for trusting the token. Everything is decoded locally in your browser, the token never leaves your machine, and you can even inspect production tokens without worrying about leaking them to a third-party server.

✨ Key Features


  • Three-part decoding: handles base64url and multi-byte UTF-8 characters correctly
  • Two-pane view: Header and Payload rendered as pretty JSON code blocks
  • Claim table: recognises registered claims with a plain-language explanation
  • Timestamp conversion: exp, iat and nbf are converted to local date and time
  • Expiry banner: tells you valid, expiring soon or already expired against now
  • Fully local: the token never leaves the browser, with copy and JSON export

📝 How to Use


  1. Copy the complete three-part JWT from an API response or debugging tool
  2. Paste it into the top input, or click Example to load a demo token
  3. Click Decode and wait for the Header and Payload to be displayed
  4. Read the status banner to check whether the token is still valid
  5. Copy a segment or export the decoded result as a JSON file as needed

⚠️ Notes


  • No signature verification: this tool only decodes Header and Payload; the real signature must be verified by the server
  • Not confidential: the Payload is base64url-encoded, not encrypted, so never put passwords or secrets inside it
  • Three parts required: a JWT must have three dot-separated segments, otherwise a friendly error is shown
  • Timezone: the expiry check uses your browser local time and may differ from the server timezone
  • Privacy: all decoding happens locally and the token is never uploaded, so it is safe to debug

Related

⏫︎