Decode compact JWT headers and payloads locally in your browser. Inspect common claims and timestamp windows; decoding does not verify the signature or establish that the token is authentic.
What is a JWT?
A JSON Web Token (JWT) is a compact format for carrying claims between parties. A signed JWT can help a recipient detect changes when the recipient verifies the signature using the expected algorithm and trusted key.
JWT Structure
A compact JWT is commonly written as header.payload.signature. The first two segments are Base64URL-encoded JSON. The signature segment contains encoded signature data; reading any segment does not establish that the signature is correct.
How to Decode a JWT
Paste a compact token and select Decode. The tool trims surrounding whitespace, decodes the header and payload as UTF-8 JSON, and shows the third segment as encoded metadata. Copy Header, Copy Payload, or Copy Token when needed.
JWT Claims
Common claims include iss (issuer), sub (subject), aud (audience), exp (expiration), nbf (not before), iat (issued at), and jti (token ID). Numeric exp, nbf, and iat values are Unix timestamps; the tool displays their UTC dates when representable.
Decode vs Verify
Decoding only reveals the encoded header and payload. It does not check a signature, prove who issued the token, or establish that the claims are trustworthy. Signature verification requires an appropriate cryptographic process, the expected algorithm, and a trusted key or trust configuration.
Is It Safe to Decode a JWT?
This tool performs decoding in the browser and does not upload or save the token. A JWT may still contain sensitive information, and browser extensions, shared devices, or untrusted websites can affect privacy. Avoid pasting production credentials into websites unless you trust the environment.
JWT Decoder Features
- Decode Base64URL header and payload segments as UTF-8 JSON
- Inspect arbitrary header fields, payload fields, and standard claims
- Display exp, nbf, and iat timestamps in UTC
- Show local exp/nbf timestamp status without claiming verification
- Copy the header, payload, or trimmed token
Frequently Asked Questions
Does decoding verify the token signature?
No. The signature is displayed only as encoded text metadata. This tool does not verify it or determine whether the token is authentic.
What does the expiration status mean?
It compares the numeric exp claim with this device’s current clock. It is a local timestamp check only and does not verify the signature, issuer, audience, or server-side acceptance.
Is my token sent to a server?
No. Decoding happens in your browser, and the token is not sent to ToolCoda servers or an external API by this tool.
Can a JWT payload be read without its signing key?
Often, yes: signed JWT payloads are encoded, not encrypted. Do not treat a signature as confidentiality; encrypted JWT formats have different structures and are not decrypted by this tool.