JWT Decoder

Decode JSON Web Tokens and read their claims.

JWT Decoder – Decode JSON Web Tokens Online

The JWT decoder reads a JSON Web Token and shows its header, payload, and signature as formatted JSON. Registered claims are explained, timestamps such as exp, iat, and nbf are converted to readable dates, and you see at a glance whether the token has expired.

Anatomy of a JWT

A JWT looks like xxxxx.yyyyy.zzzzz — three Base64URL-encoded parts separated by dots:

  1. Header – the token type and signing algorithm, e.g. {"alg": "HS256", "typ": "JWT"}, sometimes a key ID (kid).
  2. Payload – the claims: who the token is about (sub), who issued it (iss), who it's for (aud), when it expires (exp), plus custom data such as roles or email.
  3. Signature – proves the header and payload weren't changed, created with a secret or private key.

What the decoder shows

  • Pretty-printed header and payload JSON (UTF-8 safe, so names like "Çağrı" display correctly).
  • A claims table with the meaning of standard claims.
  • Human-readable dates for time claims, with ISO 8601 values.
  • Expiry status: expired, still valid, or no expiry at all.
  • Clear errors for malformed tokens, JWEs, or payloads that aren't JSON.

You can paste the raw token or a full Authorization: Bearer … value — the Bearer prefix is removed automatically.

Decoding is not verifying

Anyone can decode a JWT; that's by design. The security comes from the signature, which only your server can verify with the right key. Use this tool for debugging login flows, checking scopes and roles, and finding out why a token is rejected (often an expired exp or a wrong aud).

Inspect Base64URL data directly with the Base64 Encoder / Decoder, or explore the decoded payload in the JSON Viewer.

Frequently Asked Questions

Decoding happens entirely in your browser; the token isn't sent anywhere. Still, a JWT is a credential: anyone holding a valid, unexpired token can use it. Prefer test tokens or expired ones, and never share live tokens in chats or tickets.

No. The header and payload are only Base64URL-encoded, so anyone can read them without a key. Verification needs the secret (HS256) or public key (RS256/ES256) and must happen on your server. Never trust a token's claims just because it decodes.

They are Unix timestamps in seconds: exp is when the token expires, iat when it was issued, and nbf the time before which it must not be accepted. The decoder shows them as readable dates and tells you whether the token has expired.

A JWT has three dot-separated parts. Tokens with five parts are encrypted JWEs, whose payload can't be read without the key. Opaque access tokens (random strings) aren't JWTs at all and contain no readable data.