JWT Decoder
Decode JWT header and payload locally. Inspect issue and expiry times without sending your token anywhere.
Processed on your device. Your files and inputs never leave your browser.
How it works
Paste a three-part JWT
Decode the Base64URL header and payload as formatted JSON.
Review timestamps and expiry information. Signature verification is not performed.
A signed JWT usually has three dot-separated segments: header, payload, and signature. Decoding exposes readable claims but does not establish who created them. Anyone can construct a token with arbitrary claims. An unexpired exp value is not proof that a token is valid; authorization requires signature, issuer, audience, and other application checks. Encrypted five-part JWE tokens are not supported.
A few more useful tools
Good to know
Does decoding verify a JWT?
No. Decoding a JWT does not verify its signature or authenticity. Never use the decoded output alone to grant access.
Is my token stored in browser history?
No. Tokens stay in component memory and are never put in URLs, localStorage, analytics, or logs. Clear the field when you are finished.