JWT Decoder
Decode & inspect JSON Web Tokens locally
Everything runs in your browser. Your token is never uploaded, logged, or stored on a server.
A JWT is three Base64url chunks joined by dots, and the first two, the header and the payload, are just JSON once you decode them. This tool decodes them as you type, highlights the JSON, and turns the timestamp claims like exp and iat into real dates so you can see right away whether a token is still good. It never asks for your signing secret and never sends the token anywhere. That last part matters, because plenty of online decoders quietly ship your production token off to their server.
What a JWT is
A JWT is a compact way to carry claims, which are just statements about a user or a session, from one service to another. It's one string in three parts split by dots: header.payload.signature. The header and payload are plain JSON that's been Base64url-encoded. The signature is a cryptographic stamp that proves the header and payload haven't been changed since they were issued.
The three parts
- The header describes how the token is signed: the alg (the algorithm, like HS256 or RS256) and the typ, which is almost always JWT.
- The payload holds the claims. Standard ones include iss (who issued it), sub (who it's about), aud (who it's for), iat (when it was issued), nbf (not valid before this time), and exp (when it expires). The issuer can add its own custom fields too.
- The signature is calculated from the header and payload using a secret or a private key. It lets whoever receives the token confirm it's real and untouched, but only if they have the matching key.
eyJhbGciOiJIUzI1NiJ9 . eyJzdWIiOiJDYXQifQ . <signature> └─ header (JSON) └─ payload (JSON) └─ verification
Decoding vs verifying
This is the part that matters most, and it's why this tool runs locally. The header and payload aren't encrypted, only Base64url-encoded. Anyone who has the token can read everything in it. So don't put anything secret in a payload, because it's effectively public to whoever holds the token. Decoding just reverses that Base64url and shows you the JSON.
Verifying is a different, stronger step. It recomputes the signature using the key and checks that it matches, which proves the token is genuine and hasn't been tampered with. Decoding tells you what a token claims. Verifying tells you whether you can trust those claims.
Reading expiry and timestamps
The time claims, exp, iat, and nbf, are stored as Unix timestamps, which is the number of seconds since the start of 1970. Nobody reads those at a glance. This tool converts them to your local date and time and tells you whether the token is still active or already expired, since checking expiry is by far the most common reason to decode a token in the first place.