Skip to main content

JWT Decoder

Decode and inspect JSON Web Tokens — header, payload, and expiry at a glance. Runs in your browser — your input never leaves your device.

Specifications

Accepts
Text — type or paste
Gives you
copy to clipboard
Where it runs
Your browser — the file is never uploaded
Sign-up
None
Cost
Free, with no usage limits

About JWT Tokens

  • A JWT consists of three Base64URL-encoded parts: Header, Payload, and Signature, separated by dots.
  • The header declares the token type and signing algorithm (e.g. HS256, RS256).
  • The payload contains claims — registered (sub, iat, exp, nbf) and custom ones.
  • The signature verifies the token's integrity — validation requires the secret key on your server.
  • This tool decodes entirely in your browser. The token never leaves your device.

The registered claims, and what they mean

Seven claim names are reserved by RFC 7519. Everything else in a payload is application-specific, so if you are staring at a claim not listed here, it was defined by whoever issued the token.

Claim Name What it carries
iss Issuer Who minted the token. Your API should check this matches the issuer it trusts, not just that a signature verifies.
sub Subject Who or what the token is about — usually a user id. Unique within the issuer, not globally.
aud Audience Who the token is for. A token minted for one service should be rejected by another, and this is the claim that says so.
exp Expiration time Seconds since 1 Jan 1970 after which the token must be rejected. Decoded above into a real date, with the time remaining.
nbf Not before The token is invalid until this moment. Rare, and a common cause of "it works on my machine" when clocks disagree.
iat Issued at When the token was created. Useful for deciding a token is too old even if it has not formally expired.
jti JWT ID A unique id for this token, so it can be revoked or stopped from being replayed.

All three time claims are Unix timestamps in seconds — not milliseconds, which is the classic bug when a JavaScript backend writes Date.now() straight into exp and produces a token that expires in the year 56000. To read one by hand, or to check a value before putting it in a token, use the Unix Timestamp Converter.

Decoding is not verifying

This tool reads a token. It does not, and cannot, tell you the token is genuine — the payload is Base64URL, not encryption, so anyone holding a token can read it and anyone can write a new one with whatever claims they like. What stops a forged token is the signature, and checking that requires the secret or public key, which belongs on your server and should never be pasted into a web page.

The practical consequence: never trust a claim in a token your backend has not verified, and never put anything in a payload you would mind a user reading. If you need a signed token to test against, the JWT Generator builds one with your own secret, also without it leaving your browser.

Related Tools

Related guide

What Is a JWT and How to Decode One Background reading on this page's topic