Available now

JWT Decoder

Decode a JWT locally and inspect its header, payload, and time claims.

Developer Tools

Decoding runs locally in this browser. The token is not uploaded or saved by this tool.

Treat JWTs as sensitive credentials. Never paste production access tokens into websites you do not trust.

Surrounding whitespace is trimmed when you select Decode. The token is not decoded as you type.

The Example button loads synthetic data with a demonstration-only signature.

Decode compact JWT headers and payloads locally in your browser. Inspect common claims and timestamp windows; decoding does not verify the signature or establish that the token is authentic.

What is a JWT?

A JSON Web Token (JWT) is a compact format for carrying claims between parties. A signed JWT can help a recipient detect changes when the recipient verifies the signature using the expected algorithm and trusted key.

JWT Structure

A compact JWT is commonly written as header.payload.signature. The first two segments are Base64URL-encoded JSON. The signature segment contains encoded signature data; reading any segment does not establish that the signature is correct.

How to Decode a JWT

Paste a compact token and select Decode. The tool trims surrounding whitespace, decodes the header and payload as UTF-8 JSON, and shows the third segment as encoded metadata. Copy Header, Copy Payload, or Copy Token when needed.

JWT Claims

Common claims include iss (issuer), sub (subject), aud (audience), exp (expiration), nbf (not before), iat (issued at), and jti (token ID). Numeric exp, nbf, and iat values are Unix timestamps; the tool displays their UTC dates when representable.

Decode vs Verify

Decoding only reveals the encoded header and payload. It does not check a signature, prove who issued the token, or establish that the claims are trustworthy. Signature verification requires an appropriate cryptographic process, the expected algorithm, and a trusted key or trust configuration.

Is It Safe to Decode a JWT?

This tool performs decoding in the browser and does not upload or save the token. A JWT may still contain sensitive information, and browser extensions, shared devices, or untrusted websites can affect privacy. Avoid pasting production credentials into websites unless you trust the environment.

JWT Decoder Features

  • Decode Base64URL header and payload segments as UTF-8 JSON
  • Inspect arbitrary header fields, payload fields, and standard claims
  • Display exp, nbf, and iat timestamps in UTC
  • Show local exp/nbf timestamp status without claiming verification
  • Copy the header, payload, or trimmed token

Frequently Asked Questions

Does decoding verify the token signature?

No. The signature is displayed only as encoded text metadata. This tool does not verify it or determine whether the token is authentic.

What does the expiration status mean?

It compares the numeric exp claim with this device’s current clock. It is a local timestamp check only and does not verify the signature, issuer, audience, or server-side acceptance.

Is my token sent to a server?

No. Decoding happens in your browser, and the token is not sent to ToolCoda servers or an external API by this tool.

Can a JWT payload be read without its signing key?

Often, yes: signed JWT payloads are encoded, not encrypted. Do not treat a signature as confidentiality; encrypted JWT formats have different structures and are not decrypted by this tool.

Keep exploring

Related tools

Learn more