JWT Decoder
Paste any JSON Web Token to inspect its header and payload, check claim expiration, and copy decoded JSON—100% client-side.
🔒 Tokens never leave your browser.
Quick Answer
A JSON Web Token (JWT) is a compact, URL-safe way to represent claims, such as a user identity, between parties. It has three dot-separated parts—header, payload, and signature—each base64url-encoded. Use this free online JWT decoder to paste any token and instantly inspect its header and payload, check expiration (exp), not-before (nbf), and issued-at (iat) claims, and view pretty-printed JSON. Everything runs in your browser; nothing is ever uploaded.
How It Works
Paste your JWT in the text area—decoding happens live as you type, no button needed
Inspect the decoded Header (algorithm, type) and Payload (claims) rendered as pretty-printed JSON
Check the claim badges: Expired / Expires in (exp), Not valid yet (nbf), and Issued (iat) status
Use the Copy JSON buttons to copy the header or payload to your clipboard
Key Facts
- A JWT has three dot-separated parts: header, payload, and signature (2 parts = unsigned token)
- Each part is base64url-encoded, so decoding is instant, lossless, and done fully in the browser
- Decoding is not decryption—anyone can read a JWT’s header and payload
- Never put secrets (passwords, API keys) in the payload; it is publicly readable
- Standard claims: exp (expiration), iat (issued at), nbf (not before), sub (subject), iss (issuer)
- Common header alg values: RS256, HS256, ES256—and "none", which is dangerous when accepted
- The signature proves integrity, but only the issuer’s key or shared secret can verify it
- All processing is 100% client-side—your token never leaves your browser
Frequently Asked Questions
What is a JWT?
A JSON Web Token (JWT) is a compact, URL-safe token format for carrying claims—such as "user 123 is logged in"—between a server and a client. It consists of a header (algorithm and type), a payload (the claims), and a signature (which proves the token was issued by a trusted party). Each part is base64url-encoded and the parts are joined with dots.
Is decoding a JWT the same as decrypting it?
No. JWTs are signed, not encrypted (unless a JWE is used). Base64url decoding only reverses the encoding—anyone with the token can read its header and payload. The signature protects integrity, not confidentiality, so never store secrets in the payload.
Why does a JWT have three parts?
The first part is the header, declaring the token type and signing algorithm (e.g., RS256). The second is the payload, carrying the claims such as user id and expiration. The third is the signature, computed by the issuer with its key or shared secret. Unsigned tokens (alg: none) have only two parts. This tool also handles the two-part case and tells you which one you have.
What does 'alg: none' mean and why is it dangerous?
"alg: none" means the token has no signature—anyone can forge one. It is only legitimate for intentionally unsecured flows. It is dangerous because a vulnerable server-side library may accept a token claiming "none" and skip signature verification entirely, letting an attacker craft valid-looking tokens. If this tool shows an alg-none warning, treat the token as untrusted.
How do I check if a JWT is expired?
Look at the exp claim in the payload—it is a Unix timestamp in seconds. If exp is in the past, the token is expired. This tool computes it for you and shows a red "Expired N ago" badge or a green "Expires in N" badge. It also checks nbf (not valid yet) and iat (issued at) when present.
Is it safe to paste my JWT into this tool?
Yes. All decoding happens locally in your browser using JavaScript APIs (atob and TextDecoder). The token is never sent to any server, logged, or stored—closing the tab discards it. Note that anyone who already has the token can decode it too, so treat tokens like passwords: don’t share them in public places.