JWT Decoder

Decode a JSON Web Token header and payload (base64url) to inspect claims.

The JWT Decoder splits a JSON Web Token into its header and payload and shows the claims as readable JSON. A JWT is made of three base64url parts: the header (algorithm and type), the payload (the claims, including exp, iat, sub, and custom fields), and the signature. Decoding lets you see exactly what a token asserts without needing the signing key. This is invaluable when debugging authentication, checking whether a token has expired, or understanding what an API provider returned. Keep in mind that decoding is not verification: it does not prove the signature is valid, so treat the claims as informational only and verify signatures on the server. A JSON Web Token is three base64url segments joined by dots, and decoding it is a matter of splitting the string and reading each part as JSON. The header names the signing algorithm and the token type; the payload carries the claims, including the registered ones such as issuer, subject, audience, expiration, and issued at, plus whatever custom fields the issuer decided to add; the signature is what a server uses to prove the first two parts were not altered. Seeing the claims in readable form is the fastest way to answer practical questions: has this token already expired, which user or service does it represent, and does it carry the scope I expected. It is equally useful when you are wiring up an integration and need to confirm the provider is sending the fields the documentation promised. The essential caveat is that decoding is not verification. Reading the payload proves nothing about authenticity, because anyone can craft a token with any claims; signature checking happens on the server with the secret or public key, and that step is what actually makes a token trustworthy.

Private by design. Every tool runs 100% in your browser — your code, text, and tokens never leave your device. Nothing is uploaded or stored.
This decodes the token locally so you can inspect its claims. It does not verify the signature, so a token's authenticity is not confirmed.
Header

Decoded header appears here.

Payload

Decoded payload appears here.

Frequently Asked Questions

Is decoding a JWT the same as verifying it?

No. Decoding only base64url-decodes the payload so you can read claims; it does NOT check the signature. Never trust decoded claims without signature verification on the server.

Why can I read the payload if it is signed?

JWTs are signed, not encrypted. The signature proves integrity, but the payload is plainly readable by anyone holding the token — never put secrets in a JWT.

What do exp and iat mean?

exp is the expiry timestamp; iat is issued-at. Both are Unix seconds. The decoder shows them as human dates so you can spot expired tokens.

Related tools from our network

A focused set of free calculators and guides across related topics — no account required.