03 / API & Auth / jwt-decoder

JWT Decoder

Decode JWT header, payload and claims in your browser.

ReadyLocal processing
03 · Workspace

How to use

  1. 01Paste a JSON Web Token into the input area.
  2. 02The header and payload decode instantly as you type.
  3. 03Review registered claims such as iss, sub, exp and iat in the claims table.
  4. 04Check the expiry banner to see whether the token is still valid.

What is this tool?

A JWT decoder splits a token into its header, payload and signature and Base64URL-decodes the first two sections. Decoding does not verify the signature — it only reveals what the token claims. All decoding runs locally in your browser.

Common use cases

  • Inspecting claims while debugging authentication issues
  • Checking whether an access token has expired
  • Confirming which algorithm an identity provider used
  • Understanding scopes and roles embedded in a token

FAQ

Does this verify the signature?

No. It decodes the token; it does not validate authenticity.

Is my token sent to a server?

No. Decoding happens entirely in your browser.

Why does decoding fail?

A JWT needs three Base64URL sections separated by periods.

Can anyone read my JWT?

Yes — payloads are encoded, not encrypted. Never store secrets in them.