JWT Decoder
Decode a JSON Web Token and read its header, claims and expiry.
Paste a token on the left.
How it works
A JWT is three Base64URL segments separated by dots: a header naming the signing algorithm, a payload of claims, and a signature over the first two. Decoding the first two is arithmetic anyone can do — which is the single most important thing to understand about the format. A JWT is not encrypted. Everything in the payload is readable by anyone holding the token, so nothing secret belongs in one.
Decoding is also not verification. Only a party holding the issuer's signing key can establish that a token is genuine and unmodified. This page never asks for that key and never checks the signature; the third segment is shown verbatim and left alone. Treat every value here as what the token claims, not as fact.
The checks it does run
Structural things that can be judged from the token alone: an alg of none, an empty
signature, a missing or already-past exp, an nbf still in the future, a lifetime longer
than a day, and an absent aud. Each is reported with its reason rather than a bare score.
Unicode
Segments are decoded to bytes and then read as UTF-8 in strict mode. A payload containing non-ASCII names decodes correctly; a segment that is not valid UTF-8 is reported as an error rather than silently rendered as replacement characters that would look like a successful decode.
Example
A token whose header is {"alg":"none","typ":"JWT"} decodes fine and is flagged immediately: it
carries no signature at all, so any server that accepts it is trusting whatever the payload says. That is the
classic JWT implementation flaw, and it is visible from the decoded header alone.
Frequently asked questions
Is my token sent anywhere?
No. Decoding is Base64URL and JSON parsing, both of which happen in your own tab. A JWT is a live credential, so this tool makes no network request at all — you can verify that with your browser devtools network panel open.
Why does it say the signature is unverified?
Because it is. Anyone can decode a JWT; only a party holding the signing key can verify one. A decoded payload tells you what the token claims, not whether those claims are trustworthy.
What do exp, iat and nbf mean?
They are Unix timestamps: exp is when the token stops being valid, iat when it was issued, and nbf the earliest time it may be used. Each is shown here as both the raw number and a readable date.
It says my token is malformed — why?
A JWT is three Base64URL segments separated by dots. A missing segment, a stray newline from copying, or standard Base64 padding characters will all fail to parse; the tool reports which of the three segments is at fault.
Related tools
JWT Security Inspector
Check a decoded token against the weaknesses that show up in real audits.
LocalBase64 Decoder
Decode Base64 and Base64URL back to text or raw bytes.
LocalJSON Formatter & Validator
Format, validate and measure JSON, with errors located by line and column.
LocalUnix Timestamp Converter
Convert between Unix time and readable dates in UTC or local time.
LocalSAML Response Decoder
Decode a SAMLResponse and read its issuer, subject, conditions and attributes.
LocalRegex Tester
Test a pattern against sample text with a hard execution timeout.
Local