JWT Token Decoder
Decode and inspect JWT tokens without a secret key.
About JWT Decoder
Paste any JSON Web Token and instantly decode the header and payload claims. View the algorithm, issuer, subject, expiry time (with human-readable date), and all custom claims. Useful for debugging auth issues without needing the signing secret.
Use Cases
Debugging auth failures, inspecting token claims during development, checking token expiry, reviewing JWT structure in API testing, learning about JWT format.
How It Works
JWT tokens are base64url-encoded strings. The tool splits the token on dots, decodes each part with atob() and JSON.parse(), then formats the claims. Signature is not verified — decoding only.
FAQs
Does it verify the signature?
No. This tool only decodes the header and payload. Signature verification requires the secret key or public certificate.
Is it safe to paste my production tokens?
Everything runs in your browser — nothing is sent to any server. But as a best practice, rotate sensitive production tokens after debugging.
What JWT formats are supported?
Standard 3-part JWTs (header.payload.signature). Both JWS and plain unsigned JWTs are supported.