What is JWT Decoder?
A JWT carries signed claims between parties. Decoding is not verification — anyone can read payload bytes if they have the string.
How to use JWT Decoder
- Paste a JWT string (three dot-separated parts).
- Read decoded header algorithm and payload claims.
- Compare exp timestamp to current time for expiry bugs.
- Never treat decoded data as trusted without signature verification.
Worked examples
Concrete numbers and cases you can check against the tool above.
Expired token debug
Payload exp in the past explains 401 errors without guessing server clocks.
When to use JWT Decoder
Debugging OAuth and API auth requires reading exp, iss, and scope claims quickly. Local decode avoids logging tokens in server access logs.
Common use cases
- Inspect a staging access token from browser devtools.
- Teach JWT structure in security workshops.
- Check whether roles claim matches database groups.
- Confirm clock skew issues on exp and nbf fields.
Inputs and outputs
- Base64URL-encoded JWT compact serialization
- JSON pretty-print for header and payload
Privacy
This tool runs entirely in your browser. Your data never leaves your device — nothing is uploaded to our servers.
Frequently asked questions
- Does this validate signatures?
- No. Use your auth server or SDK with the secret or public key to verify.
- Is pasting production tokens safe here?
- Decoding is local, but tokens are secrets — prefer staging tokens or redact.
- Why is my payload empty?
- Malformed base64 or truncated strings fail decode — copy the entire token.