1. Home
  2. Developer Tools
  3. JWT Decoder

Free JWT Decoder & Inspector

Paste a JSON Web Token to instantly decode header, payload, and claims — expiry countdown, no signup, nothing ever leaves your browser.

✓ Free Forever✓ No Signup✓ 100% Client-Side✓ Token Never Uploaded
Ready

How to use JWT Decoder

1

Paste your JWT

Paste the full token (three dot-separated parts) into the box, or load the sample.

2

Read the claims

The header, payload claims, and expiry status decode instantly — timestamps are humanized.

3

Copy what you need

Copy the header or payload JSON with one click. Everything stays in your browser.

Frequently Asked Questions

Is this JWT decoder safe to use?

Yes, completely safe. This tool decodes JWT tokens entirely in your browser using JavaScript. Your token is never sent to any server — it never leaves your device. This is the same approach used by jwt.io. We recommend against pasting production tokens with sensitive payloads into any online tool, but the decoding itself is purely local.

What is a JWT token and what are its parts?

A JSON Web Token (JWT) has three base64url-encoded parts separated by dots: Header (algorithm and token type), Payload (claims like user ID, roles, expiry), and Signature (used to verify the token wasn't tampered with). Only the header and payload can be decoded without the secret key — the signature verification requires the server's secret.

Can this tool verify the JWT signature?

Signature verification requires the secret key or public certificate used to sign the token — information that stays on your server. This tool decodes (not verifies) the header and payload, which is useful for debugging, inspecting claims, and checking expiry. For signature verification in production, use your backend’s JWT library.

What do common JWT claims mean?

sub — Subject (user ID). iss — Issuer (who created the token). aud — Audience (intended recipient). exp — Expiry timestamp (Unix epoch). iat — Issued at timestamp. nbf — Not before (token not valid until this time). jti — JWT ID (unique token identifier).