πŸ” JWT Decoder β€” Header and Payload

Paste a JWT to inspect its header and claims locally. Nothing is uploaded. Signature verification is intentionally not performed.

Security Free Β· no sign-up Added 2026-10-06
Input
Result
Token info

Private by design. This tool runs entirely in your browser β€” nothing you enter or add is uploaded to any server.

How it works

  1. Paste a token with three base64url segments separated by dots.
  2. Press Decode. The header and payload are decoded and formatted as JSON when possible.
  3. Read the claim timestamps if present. The signature segment is shown only as a length, not verified.

Examples

  • A token whose payload includes exp shows that claim as a Unix time and a local date.
  • A two-segment string is rejected because a JWT has header, payload and signature.
  • Payloads that are not JSON are shown as decoded text instead of formatted JSON.

Frequently asked questions

Does this verify the signature?

No. Decoding only reveals what the token claims. Trust a token only after a server verifies it with the correct key.

Is the token uploaded?

No. Decoding uses the browser only. Still avoid pasting production secrets into a shared or logged machine.

What is the exp claim?

exp is the expiry time as seconds since 1970-01-01 UTC. iat is issued-at and nbf is not-before, when those claims exist.