JWT Decoder
Paste a three-part JWT to decode its header and payload, view the signature string, and check expiration when an exp claim is present. This is an inspection tool only; it does not verify the token signature.
How to Use JWT Decoder
- Copy your JWT token from your application, API response, or browser developer tools.
- Paste the token into the text area. The decoder processes it automatically as you type.
- View the decoded header, payload, and signature. If an expiration claim is present, the tool shows whether the token is still valid.
Features
- Decodes any standard JWT with three Base64url-encoded parts
- Pretty-prints header and payload as formatted JSON
- Automatic expiration check with color-coded valid/expired indicator
- Real-time decoding as you type or paste
- Clear error messages for malformed tokens
- Decodes with JavaScript in the browser tab
- Decoder only: signature verification must happen in your application or auth system
JWT Decoder: inspect header, payload, and exp
Use JWT Decoder to inspect a three-part JSON Web Token by decoding its Base64url header and payload. The page also displays the signature segment and can show whether an exp claim is already expired.
Example workflow
Paste a token from an API response, read the formatted payload claims, and check the expiration status. Treat the decoded values as readable data, not proof that the token is valid or trusted.
Limits to check
- Token shape: The decoder expects exactly three dot-separated JWT parts.
- Signature: The signature string is shown but not verified.
- Trust: Verify the signature with the correct key in your application or authentication system before relying on the token.
For the next step, try JSON Formatter & Validator, Regex Tester & Log Extractor, Base64 Encoder & Decoder, Hash Generator.
Frequently Asked Questions
What is a JWT token?
JWT (JSON Web Token) is a compact token format often used by web applications for authentication and authorization data. A standard JWT has three dot-separated parts: header, payload, and signature.
Does this tool verify the JWT signature?
No. Signature verification requires the secret key or public key used to sign the token. This tool only decodes the Base64url-encoded header and payload and displays the raw signature string.
Is decoded JWT content proof that the token is trusted?
No. Decoded JWT content is only readable data. Verify the signature with the correct key in your application or authentication system before relying on the token.
What JWT algorithms are supported?
The decoder can display the algorithm field from any standard JWT header because it only decodes the Base64url-encoded JSON. It does not validate HS256, RS256, ES256, or any other signature algorithm.
Why does the expiration check show the wrong time?
The expiration is displayed in your local browser timezone using JavaScript's Date.toLocaleString(). JWT exp claims are Unix timestamps in seconds since January 1, 1970 UTC.