API Toolkit

JWT Decoder

All tools

Decode JWT tokens. - runs entirely in your browser. Free, fast and private.

How it works

Four simple steps

1

Paste JWT token

Paste the three-part base64url token string.

2

Split header/payload

Header and claims decode to readable JSON objects.

3

Check exp/iat claims

Expiry and issued-at timestamps show in local time.

4

Copy claim JSON

Copy decoded payload for debugging auth flows.

JWT Decoder

About JWT Decoder

A support ticket says "token expired" but the clock on the claim does not match what you expect. JWT Decoder splits header and payload into readable JSON and turns iat, nbf, and exp into local timestamps.

Decode when you need to inspect alg, kid, roles, tenant IDs, or expiry without calling the issuer. This page does not prove the signature is valid. Decoding only Base64URL-parses the parts. For HS256 checks, use JWT Verify with the shared secret on the same device.

Pitfall: treating a decoded payload as trusted input. Anyone can mint an unsigned-looking JWT string. Always verify signatures in production code paths.

Tip: clear the textarea when you finish if the token is a production session JWT, not a fixture.

Tokens are parsed with browser APIs in this tab. Clear the field when you are done so the JWT is not left on a shared screen.

Features

Lightning fast

Processes data instantly with no server round-trips.

100% private

Your data never leaves your browser. Nothing is uploaded.

No installation

Works in any modern browser. Nothing to download or install.

Free forever

No limits, no sign-up, no credit card required.

Cross-platform

Works on desktop, tablet and mobile devices.

Dark & light mode

Beautiful in both themes. Your preference is saved.

Keyboard shortcut

Ctrl Enter - Run tool

Use cases

Auth debugging

See claims and expiry without guessing from opaque strings.

Expiry checks

Confirm exp/iat against local time when users report lockouts.

Prep for verify

Inspect header alg, then move to JWT Verify for HS256.

Instructions

How to use this tool

FAQ

Frequently asked questions

See all FAQs

Answers for this tool. For site-wide help, open the FAQ hub.

No. Decoding reads claims; use JWT Verify to check signatures.

JWT Decoder Decode JWT tokens. It runs entirely in your browser with instant feedback.

No server upload is required for formatting/validation. Clearing the page removes the text from memory.

Validators report problems; formatters beautify valid structure. Severely broken input may need manual fixes first.

Formatters and converters aim to preserve meaning. Always review diffs for mission-critical code before committing.

Paste smaller chunks if the tab slows down. Minifiers and deep validators scale with input size on the CPU you have.

Many tools support Ctrl/⌘+Enter to run and standard copy shortcuts. Check the tool toolbar for Sample / Clear / Download.

When options exist (spaces vs tabs, indent width), set them before copying output into your repo to match project style.

After the page loads, formatting continues offline. CDN libraries need an initial network load.

Bookmark JWT Decoder, copy output into editors, or chain steps with Recipes.

View more FAQs

Related tools

View all

Webhook HMAC Signer

Sign and verify GitHub, Stripe, and Slack webhook signatures locally.

Open

Webhook Replay Diff Lab

Compare webhook payload timelines, re-check HMAC digests, and spot idempotency gaps locally.

Open

JSONPath Playground

Query JSON with JSONPath and JMESPath-style paths side by side.

Open

GraphQL Studio

Format, validate, and cost-estimate GraphQL documents with cURL export.

Open

Explore 321 free tools

Everything you need as a developer, marketer or creator - in one beautiful place.

Browse all tools