Free Online JWT Decoder
Debugging auth? Paste any JWT (JSON Web Token) to instantly decode its header and payload, see claims like sub, exp, and roles in readable form, and check whether the token has expired — all in your browser, tokens never uploaded.
Header
—
Payload (claims)
—
✓ Free forever · ✓ No signup · ✓ Runs in your browser — your data never leaves your device.
How to Use the JWT Decoder
- Paste the full JWT (the three dot-separated segments) into the box.
- Click Decode Token — header and payload appear as formatted JSON.
- Read the expiry badge to see if the token is still valid.
- Never paste production secrets into any online tool you don't trust — this one runs 100% locally.
Why Use Our JWT Decoder?
- Instant decode — header, payload, and signature split and pretty-printed.
- Expiry check — exp/iat/nbf claims translated to human-readable dates with a valid/expired badge.
- Malformed-token detection — clear errors instead of silent garbage.
- Fully private — decoding runs in your browser; tokens never leave your device.
Frequently Asked Questions
What is a JWT?
A JSON Web Token: three base64url segments (header.payload.signature) used for authentication. The payload carries claims like user ID and expiry.
Can this tool verify the signature?
Signature verification needs the secret key, which you should never share. This tool decodes the readable parts; verification belongs on your server.
Why does my token show as expired?
The exp claim is a Unix timestamp. If it's in the past, the token is expired — request a fresh one from your auth server.
Is it safe to paste tokens here?
This tool runs entirely in your browser and never transmits your token. As a rule, prefer decoding tokens locally rather than on unknown sites.
What's the difference between JWT and JWE?
JWTs are signed but readable (payload is only base64-encoded). JWE tokens are encrypted and can't be decoded without the key.