142+ Free Online Tools · Easy. Fast. Accurate.

JWT Decoder

Decode a JSON Web Token to inspect its header and payload, instantly in your browser.

How to use the JWT Decoder

  1. Paste the full JWT, the three dot-separated parts beginning with eyJ.
  2. Click Run to see the decoded header and payload as formatted JSON.
  3. Check claims such as alg, exp (expiry), iat (issued at) and sub (subject).

How the JWT Decoder works

A JWT has three Base64URL-encoded parts separated by dots: a header describing the signing algorithm, a payload containing the claims, and a signature. The header and payload are encoded, not encrypted, so anyone holding the token can read them. The decoder splits the token, converts Base64URL back to standard Base64, decodes it and pretty-prints the JSON.

Decoding does not verify the signature, so it can't tell you whether a token is genuine or has been tampered with; your server must do that with the secret or public key. Time claims like exp are Unix timestamps that you can read with the Unix Timestamp Converter.

Frequently asked questions

Is this tool free?
Yes. Decode JWTs at no cost, with no account required.
Does this verify the signature?
No. This tool only decodes the header and payload, which are not encrypted, just Base64URL encoded. It does not verify the signature.
Does my token leave my browser?
No. Decoding happens entirely client-side; your token is never sent to a server.

More Developer Tools

Browse all Developer Tools →