Code Tools StudioCode Tools Studio
All Tools
Tools
JSON FormatterCode MinifierRegex TesterPDF MergePDF SplitPDF to TextImage ConverterJSON Schema GeneratorText Case ConverterBase64 Encoder/DecoderURL Encoder/DecoderHash GeneratorUUID GeneratorColor ConverterTimestamp ConverterLorem Ipsum GeneratorJWT DecoderText Diff CheckerMarkdown Previewer

Command Palette

Search tools and actions

JWT Decoder

Decode a JWT's header and payload, entirely client-side. This does not verify the signature.

Valid until 5/18/2033, 3:33:19 AM
{
  "alg": "HS256",
  "typ": "JWT"
}
{
  "sub": "usr_1a2b3c",
  "name": "Ada Lovelace",
  "role": "admin",
  "iat": 1700000000,
  "exp": 1999999999
}

About JWT Decoder

The JWT Decoder splits a JSON Web Token into its header and payload so you can inspect the claims inside: expiry, subject, roles, whatever your app puts there. Decoding happens entirely client-side and does not verify the signature, so treat it as a read-only inspector, not a validator.

How to use it

  1. Paste a JWT into the token field.
  2. Review the decoded Header and Payload, shown as formatted JSON.
  3. Check the expiry badge to see at a glance whether the token's exp claim has passed.
  4. Copy the header or payload individually if you need to share just one part.

Common use cases

  • Debugging why an API is rejecting a token by inspecting its actual claims
  • Checking a token's expiry time during OAuth or session debugging
  • Confirming which roles or scopes a token carries before wiring up an authorization check

Example

Before

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c

After

Header: {"alg":"HS256","typ":"JWT"}   Payload: {"sub":"1234567890","name":"John Doe","iat":1516239022}

This is the standard jwt.io example token — the header and payload decode to exactly those two JSON objects; the signature stays unreadable without the secret key.

Common errors

"Invalid token" or decoding fails entirely

Make sure you copied all three dot-separated parts — header, payload, and signature — without truncation or extra whitespace.

Token looks expired but your app still accepts it (or vice versa)

exp is a Unix timestamp in seconds, not milliseconds — compare it against Math.floor(Date.now() / 1000), not Date.now() directly.

Treating a successfully decoded token as trustworthy

Decoding never verifies the signature — an expired or forged token decodes exactly like a valid one. Signature verification has to happen server-side with the actual key.

FAQ

Does this verify the token's signature?

No. It only decodes and displays the header and payload; it never validates the signature, so an expired, forged, or tampered token will still decode and display normally. Always verify signatures server-side.

Is my token sent anywhere?

No. The token is decoded entirely in your browser using base64url decoding; nothing is transmitted.

What's the difference between decoding and validating a JWT?

Decoding (what this tool does) reads the header and payload without checking anything. Validating additionally verifies the signature and checks claims like expiry — that requires your app's secret or public key, which a client-side inspector like this never has access to.

Related tools

Base64 Encoder/DecoderTimestamp Converter
Code Tools Studio - 19 privacy-first tools for everyday developer tasks | Product Hunt
Files auto-deleted after 1 hour TLS 1.3 encrypted 99.9% uptime
PrivacyTermsBlog

© 2026 Code Tools Studio. All rights reserved.