JWT Decoder
Decode and inspect JSON Web Tokens — header, payload, and expiry at a glance. Runs in your browser — your input never leaves your device.
Header
Payload
Signature
Signature verification requires the secret key and cannot be performed client-side securely. The token structure and claims above are decoded from the token itself without verification.
Specifications
- Accepts
- Text — type or paste
- Gives you
- copy to clipboard
- Where it runs
- Your browser — the file is never uploaded
- Sign-up
- None
- Cost
- Free, with no usage limits
About JWT Tokens
- A JWT consists of three Base64URL-encoded parts: Header, Payload, and Signature, separated by dots.
- The header declares the token type and signing algorithm (e.g. HS256, RS256).
- The payload contains claims — registered (
sub,iat,exp,nbf) and custom ones. - The signature verifies the token's integrity — validation requires the secret key on your server.
- This tool decodes entirely in your browser. The token never leaves your device.
The registered claims, and what they mean
Seven claim names are reserved by RFC 7519. Everything else in a payload is application-specific, so if you are staring at a claim not listed here, it was defined by whoever issued the token.
| Claim | Name | What it carries |
|---|---|---|
| iss | Issuer | Who minted the token. Your API should check this matches the issuer it trusts, not just that a signature verifies. |
| sub | Subject | Who or what the token is about — usually a user id. Unique within the issuer, not globally. |
| aud | Audience | Who the token is for. A token minted for one service should be rejected by another, and this is the claim that says so. |
| exp | Expiration time | Seconds since 1 Jan 1970 after which the token must be rejected. Decoded above into a real date, with the time remaining. |
| nbf | Not before | The token is invalid until this moment. Rare, and a common cause of "it works on my machine" when clocks disagree. |
| iat | Issued at | When the token was created. Useful for deciding a token is too old even if it has not formally expired. |
| jti | JWT ID | A unique id for this token, so it can be revoked or stopped from being replayed. |
All three time claims are Unix timestamps in seconds — not milliseconds, which is the classic
bug when a JavaScript backend writes Date.now() straight into exp and
produces a token that expires in the year 56000. To read one by hand, or to check a value
before putting it in a token, use the Unix Timestamp Converter.
Decoding is not verifying
This tool reads a token. It does not, and cannot, tell you the token is genuine — the payload is Base64URL, not encryption, so anyone holding a token can read it and anyone can write a new one with whatever claims they like. What stops a forged token is the signature, and checking that requires the secret or public key, which belongs on your server and should never be pasted into a web page.
The practical consequence: never trust a claim in a token your backend has not verified, and never put anything in a payload you would mind a user reading. If you need a signed token to test against, the JWT Generator builds one with your own secret, also without it leaving your browser.