S
SnapUtilsPro
Security Popular

JWT Decoder

Paste a JSON Web Token to Base64URL-decode its header and payload, view claims as JSON, and check exp/iat against your device clock. This tool never verifies signatures or attempts to crack secrets — use it for debugging auth flows, not for attacking tokens.

Runs entirely in your browser. Your data never leaves this device.

  • Decode header and payload
  • Pretty-print JWT claims
  • Expiry and issued-at checks
  • No signature verification
  • 100% client-side decoding
Workspace
Client-side · No upload

How it works

  1. Paste a JWT (header.payload.signature).
  2. We Base64URL-decode header and payload and show exp/iat checks against your device clock.
  3. We never verify signatures or attempt to crack secrets.

Key features

  • Decode header and payload
  • Pretty-print JWT claims
  • Expiry and issued-at checks
  • No signature verification
  • 100% client-side decoding

FAQ

Do you verify JWT signatures?

No. This tool only decodes header/payload for inspection. Verification belongs in your app or API gateway with trusted keys.

Why show expiry?

We compare the exp claim to your device clock as a convenience — not cryptographic validation.

Is decoding a JWT safe?

JWTs are encoded, not encrypted. Prefer staging tokens; this site processes locally only and does not store tokens.

Can this crack HS256 secrets?

No. Brute-force and cracking features are intentionally absent.

What about encrypted JWTs (JWE)?

This decoder targets compact JWS-style tokens. Encrypted JWEs are not decrypted here.

Related developer tools