JWT Decoder
Decode a JWT's header and payload, entirely client-side. This does not verify the signature.
{
"alg": "HS256",
"typ": "JWT"
}{
"sub": "usr_1a2b3c",
"name": "Ada Lovelace",
"role": "admin",
"iat": 1700000000,
"exp": 1999999999
}About JWT Decoder
The JWT Decoder splits a JSON Web Token into its header and payload so you can inspect the claims inside: expiry, subject, roles, whatever your app puts there. Decoding happens entirely client-side and does not verify the signature, so treat it as a read-only inspector, not a validator.
How to use it
- Paste a JWT into the token field.
- Review the decoded Header and Payload, shown as formatted JSON.
- Check the expiry badge to see at a glance whether the token's exp claim has passed.
- Copy the header or payload individually if you need to share just one part.
Common use cases
- Debugging why an API is rejecting a token by inspecting its actual claims
- Checking a token's expiry time during OAuth or session debugging
- Confirming which roles or scopes a token carries before wiring up an authorization check
Example
Before
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
After
Header: {"alg":"HS256","typ":"JWT"} Payload: {"sub":"1234567890","name":"John Doe","iat":1516239022}This is the standard jwt.io example token — the header and payload decode to exactly those two JSON objects; the signature stays unreadable without the secret key.
Common errors
"Invalid token" or decoding fails entirely
Make sure you copied all three dot-separated parts — header, payload, and signature — without truncation or extra whitespace.
Token looks expired but your app still accepts it (or vice versa)
exp is a Unix timestamp in seconds, not milliseconds — compare it against Math.floor(Date.now() / 1000), not Date.now() directly.
Treating a successfully decoded token as trustworthy
Decoding never verifies the signature — an expired or forged token decodes exactly like a valid one. Signature verification has to happen server-side with the actual key.
FAQ
Does this verify the token's signature?
No. It only decodes and displays the header and payload; it never validates the signature, so an expired, forged, or tampered token will still decode and display normally. Always verify signatures server-side.
Is my token sent anywhere?
No. The token is decoded entirely in your browser using base64url decoding; nothing is transmitted.
What's the difference between decoding and validating a JWT?
Decoding (what this tool does) reads the header and payload without checking anything. Validating additionally verifies the signature and checks claims like expiry — that requires your app's secret or public key, which a client-side inspector like this never has access to.