Devbelt

JWT Decoder

Decode & inspect JSON Web Tokens locally

ENCODED TOKEN
Paste a JWT to decode its header and payload.

Everything runs in your browser. Your token is never uploaded, logged, or stored on a server.

About

A JWT is three Base64url chunks joined by dots, and the first two, the header and the payload, are just JSON once you decode them. This tool decodes them as you type, highlights the JSON, and turns the timestamp claims like exp and iat into real dates so you can see right away whether a token is still good. It never asks for your signing secret and never sends the token anywhere. That last part matters, because plenty of online decoders quietly ship your production token off to their server.

What a JWT is

A JWT is a compact way to carry claims, which are just statements about a user or a session, from one service to another. It's one string in three parts split by dots: header.payload.signature. The header and payload are plain JSON that's been Base64url-encoded. The signature is a cryptographic stamp that proves the header and payload haven't been changed since they were issued.

The three parts

  • The header describes how the token is signed: the alg (the algorithm, like HS256 or RS256) and the typ, which is almost always JWT.
  • The payload holds the claims. Standard ones include iss (who issued it), sub (who it's about), aud (who it's for), iat (when it was issued), nbf (not valid before this time), and exp (when it expires). The issuer can add its own custom fields too.
  • The signature is calculated from the header and payload using a secret or a private key. It lets whoever receives the token confirm it's real and untouched, but only if they have the matching key.
eyJhbGciOiJIUzI1NiJ9 . eyJzdWIiOiJDYXQifQ . <signature>
└─ header (JSON)         └─ payload (JSON)    └─ verification

Decoding vs verifying

This is the part that matters most, and it's why this tool runs locally. The header and payload aren't encrypted, only Base64url-encoded. Anyone who has the token can read everything in it. So don't put anything secret in a payload, because it's effectively public to whoever holds the token. Decoding just reverses that Base64url and shows you the JSON.

Verifying is a different, stronger step. It recomputes the signature using the key and checks that it matches, which proves the token is genuine and hasn't been tampered with. Decoding tells you what a token claims. Verifying tells you whether you can trust those claims.

Reading expiry and timestamps

The time claims, exp, iat, and nbf, are stored as Unix timestamps, which is the number of seconds since the start of 1970. Nobody reads those at a glance. This tool converts them to your local date and time and tells you whether the token is still active or already expired, since checking expiry is by far the most common reason to decode a token in the first place.

Frequently asked questions

How do I decode a JWT?
Paste the token into the box. Devbelt splits it at the dots and decodes the header and payload from Base64url into readable JSON instantly, with no button to press.
Is it safe to decode a JWT online?
Only if the tool is genuinely local. Devbelt decodes entirely in your browser and never uploads or logs your token, so even a production token stays on your machine. Be wary of decoders that send tokens to a server.
Does this verify the signature?
No, and that's deliberate here — this decoder never asks for your secret or key. If you need to actually verify a signature, check exp/nbf/iss/aud against expected values, or run a security scan on a token, use the JWT Debugger. It does all of that locally too, still without your token or key ever leaving your browser.
How do I know if a token is expired?
Devbelt reads the exp claim and shows the expiry date in plain English with an "Expired" or "Active" badge, so you never have to convert a Unix timestamp by hand.
What are exp, iat and nbf?
They are standard JWT time claims: iat is when the token was issued, nbf is the earliest time it is valid, and exp is when it expires. Devbelt converts all three from Unix timestamps into readable local times.

Related tools