JWT Decoder
Decode JWT headers and claims locally without uploading or storing your token.
Encoded JWT
Decoded result
Paste a JWT to decode it
The header, payload, timestamps, and signature segment will appear here automatically.
Security note
Decoding is not signature verification
A decoded token may still be forged, altered, expired, or signed with an untrusted key.
What decoding does
It converts the JWT header and payload from Base64URL into readable JSON.
What decoding does not do
It does not confirm who created the token or whether the signature should be trusted.
Guide
About JWT Decoder
A JSON Web Token is a compact claims format commonly used in authentication, API authorization, OAuth, and OpenID Connect.
This decoder converts the Base64URL header and payload into readable JSON and interprets common time claims.
Decoding does not verify the signature or prove that the token should be trusted.
What the decoder shows
Inspect token metadata and claims without uploading the token.
- alg, typ, and kid headers
- iss, sub, and aud claims
- exp, iat, and nbf timestamps
- Custom application claims
- Signature segment
JWT structure
A signed JWT normally contains a header, payload, and signature separated by periods.
Decoding versus verification
A forged, expired, or untrusted token can still decode successfully. Signature and claim validation are separate requirements.
Security considerations
JWT payloads are usually readable. Do not place confidential data in an unencrypted token, and never log production tokens unnecessarily.
FAQ
Frequently asked questions
Does decoding verify a JWT signature?
No. It only reads the encoded header and payload.
Can anyone read a JWT payload?
Usually yes, because signed JWT payloads are encoded rather than encrypted.
What do exp, iat, and nbf mean?
They represent expiration, issued-at time, and not-before time.
What does alg mean?
It identifies the algorithm used to protect the token.
Why does a JWT have three parts?
They are the protected header, payload, and signature.
Is the token uploaded?
Decoding is intended to occur locally in your browser.
Continue exploring
Related tools
Useful tools for the next step in the same workflow.
JWT Signature Verifier
Verify HMAC JWT signatures and important claims locally.
Authentication
JWT Inspector
Inspect JWT claims, expiration, lifetime, and common structural security issues.
Security Tools
JWK & JWKS Inspector
Inspect JSON Web Keys, review JWKS collections, and generate RFC 7638 thumbprints.
PKI & Certificates
Base64 Encode / Decode
Encode and decode Base64 data directly in your browser.
Encoding & Data
TOTP Generator
Generate and verify time-based two-factor authentication codes.
Authentication
Secure Password Generator
Generate strong random passwords locally in your browser.
Authentication