03 / API & Auth / jwt-decoder
JWT Decoder
Decode JWT header, payload and claims in your browser.
ReadyLocal processing
03 · WorkspaceInput → Process → Output · in-browser
How to use
- 01Paste a JSON Web Token into the input area.
- 02The header and payload decode instantly as you type.
- 03Review registered claims such as iss, sub, exp and iat in the claims table.
- 04Check the expiry banner to see whether the token is still valid.
What is this tool?
A JWT decoder splits a token into its header, payload and signature and Base64URL-decodes the first two sections. Decoding does not verify the signature — it only reveals what the token claims. All decoding runs locally in your browser.
Common use cases
- Inspecting claims while debugging authentication issues
- Checking whether an access token has expired
- Confirming which algorithm an identity provider used
- Understanding scopes and roles embedded in a token
FAQ
Does this verify the signature?
No. It decodes the token; it does not validate authenticity.
Is my token sent to a server?
No. Decoding happens entirely in your browser.
Why does decoding fail?
A JWT needs three Base64URL sections separated by periods.
Can anyone read my JWT?
Yes — payloads are encoded, not encrypted. Never store secrets in them.