JWT Decoder
Paste a JSON Web Token to Base64URL-decode its header and payload, view claims as JSON, and check exp/iat against your device clock. This tool never verifies signatures or attempts to crack secrets — use it for debugging auth flows, not for attacking tokens.
Runs entirely in your browser. Your data never leaves this device.
- Decode header and payload
- Pretty-print JWT claims
- Expiry and issued-at checks
- No signature verification
- 100% client-side decoding
How it works
- Paste a JWT (header.payload.signature).
- We Base64URL-decode header and payload and show exp/iat checks against your device clock.
- We never verify signatures or attempt to crack secrets.
Key features
- Decode header and payload
- Pretty-print JWT claims
- Expiry and issued-at checks
- No signature verification
- 100% client-side decoding
FAQ
Do you verify JWT signatures?
No. This tool only decodes header/payload for inspection. Verification belongs in your app or API gateway with trusted keys.
Why show expiry?
We compare the exp claim to your device clock as a convenience — not cryptographic validation.
Is decoding a JWT safe?
JWTs are encoded, not encrypted. Prefer staging tokens; this site processes locally only and does not store tokens.
Can this crack HS256 secrets?
No. Brute-force and cracking features are intentionally absent.
What about encrypted JWTs (JWE)?
This decoder targets compact JWS-style tokens. Encrypted JWEs are not decrypted here.
Keep building
Related developer tools
Encode and decode Base64 for text, URLs, and images entirely client-side.
Generate MD5, SHA-1, SHA-256, and SHA-512 hashes using Web Crypto in your browser.
Free online REST API tester — send HTTP requests with headers and body from your browser.