F

JWT Decoder

JWT Decoder splits JSON Web Tokens into header, payload, and signature sections, showing claims as formatted JSON without verifying cryptographic signatures.

Token

Decodes locally in your browser. Signature is not verified.

What is JWT Decoder?

A JWT carries signed claims between parties. Decoding is not verification — anyone can read payload bytes if they have the string.

How to use JWT Decoder

  1. Paste a JWT string (three dot-separated parts).
  2. Read decoded header algorithm and payload claims.
  3. Compare exp timestamp to current time for expiry bugs.
  4. Never treat decoded data as trusted without signature verification.

Worked examples

Concrete numbers and cases you can check against the tool above.

Expired token debug

Payload exp in the past explains 401 errors without guessing server clocks.

When to use JWT Decoder

Debugging OAuth and API auth requires reading exp, iss, and scope claims quickly. Local decode avoids logging tokens in server access logs.

Common use cases

  • Inspect a staging access token from browser devtools.
  • Teach JWT structure in security workshops.
  • Check whether roles claim matches database groups.
  • Confirm clock skew issues on exp and nbf fields.

Inputs and outputs

  • Base64URL-encoded JWT compact serialization
  • JSON pretty-print for header and payload

Privacy

This tool runs entirely in your browser. Your data never leaves your device — nothing is uploaded to our servers.

Frequently asked questions

Does this validate signatures?
No. Use your auth server or SDK with the secret or public key to verify.
Is pasting production tokens safe here?
Decoding is local, but tokens are secrets — prefer staging tokens or redact.
Why is my payload empty?
Malformed base64 or truncated strings fail decode — copy the entire token.

Related tools

More free utilities you may need next — also listed in Text, Writing & Developer Tools and the All Tools directory.

View full category →