Decode a JWT's header and payload — locally, nothing sent.
A JSON Web Token (JWT) has three Base64URL parts: header, payload and signature. This decoder shows the header and payload as readable JSON and converts the exp claim into a human date so you can see if the token is expired. Decoding happens entirely in your browser — your token is never transmitted.
A JWT (JSON Web Token) consists of three dot-separated Base64url-encoded segments: header (algorithm & token type), payload (claims like user ID, expiration, issuer), and signature (verifies integrity). The decoder splits the token, Base64url-decodes the header and payload, and pretty-prints the JSON. The signature is not verified — this tool is for inspection only.
No. Decoding is done locally in your browser with JavaScript. Your JWT never leaves your device — safe for sensitive tokens.
No. It decodes the readable header and payload. Verifying the signature requires the secret or public key and should be done server-side.
JWT payloads are only Base64-encoded, not encrypted. Anyone can read them — never put secrets in a JWT payload.
No. Decoding only reads the header and payload. Verification cryptographically validates the signature to ensure the token was not tampered with. Always verify tokens on your server.
exp (expiration time) is a Unix timestamp indicating when the token expires. After this time, the token should be rejected by your application.