◆ Online Dev Kit

JWT Decoder

Decode a JWT's header and payload — locally, nothing sent.

About this tool

A JSON Web Token (JWT) has three Base64URL parts: header, payload and signature. This decoder shows the header and payload as readable JSON and converts the exp claim into a human date so you can see if the token is expired. Decoding happens entirely in your browser — your token is never transmitted.

Common use cases

How it works

A JWT (JSON Web Token) consists of three dot-separated Base64url-encoded segments: header (algorithm & token type), payload (claims like user ID, expiration, issuer), and signature (verifies integrity). The decoder splits the token, Base64url-decodes the header and payload, and pretty-prints the JSON. The signature is not verified — this tool is for inspection only.

FAQ

Is my token sent to a server?

No. Decoding is done locally in your browser with JavaScript. Your JWT never leaves your device — safe for sensitive tokens.

Does this verify the signature?

No. It decodes the readable header and payload. Verifying the signature requires the secret or public key and should be done server-side.

Why is the payload readable without a key?

JWT payloads are only Base64-encoded, not encrypted. Anyone can read them — never put secrets in a JWT payload.

Is decoding a JWT the same as verifying it?

No. Decoding only reads the header and payload. Verification cryptographically validates the signature to ensure the token was not tampered with. Always verify tokens on your server.

What does the "exp" claim mean?

exp (expiration time) is a Unix timestamp indicating when the token expires. After this time, the token should be rejected by your application.