JWT Decoder

Decode JWT headers and claims locally without uploading or storing your token.

Browser onlyNo uploadInstant decoding

Encoded JWT

Decoded result

Paste a JWT to decode it

The header, payload, timestamps, and signature segment will appear here automatically.

Security note

Decoding is not signature verification

A decoded token may still be forged, altered, expired, or signed with an untrusted key.

What decoding does

It converts the JWT header and payload from Base64URL into readable JSON.

What decoding does not do

It does not confirm who created the token or whether the signature should be trusted.

Guide

About JWT Decoder

A JSON Web Token is a compact claims format commonly used in authentication, API authorization, OAuth, and OpenID Connect.

This decoder converts the Base64URL header and payload into readable JSON and interprets common time claims.

Decoding does not verify the signature or prove that the token should be trusted.

What the decoder shows

Inspect token metadata and claims without uploading the token.

  • alg, typ, and kid headers
  • iss, sub, and aud claims
  • exp, iat, and nbf timestamps
  • Custom application claims
  • Signature segment

JWT structure

A signed JWT normally contains a header, payload, and signature separated by periods.

Decoding versus verification

A forged, expired, or untrusted token can still decode successfully. Signature and claim validation are separate requirements.

Security considerations

JWT payloads are usually readable. Do not place confidential data in an unencrypted token, and never log production tokens unnecessarily.

FAQ

Frequently asked questions

Does decoding verify a JWT signature?

No. It only reads the encoded header and payload.

Can anyone read a JWT payload?

Usually yes, because signed JWT payloads are encoded rather than encrypted.

What do exp, iat, and nbf mean?

They represent expiration, issued-at time, and not-before time.

What does alg mean?

It identifies the algorithm used to protect the token.

Why does a JWT have three parts?

They are the protected header, payload, and signature.

Is the token uploaded?

Decoding is intended to occur locally in your browser.

Continue exploring

Useful tools for the next step in the same workflow.