json.

JWT Decoder

Inspect JWT headers and payloads locally. This tool does not verify signatures.

Decoded locally โ€” signature is not verified.

JWT

Header

Payload

What is a JWT?

A JSON Web Token (JWT), defined in RFC 7519, is a compact, URL-safe way to represent claims between two parties. A JWT has three segments separated by dots โ€” header.payload.signatureโ€” where the header names the signing algorithm, the payload carries the claims (data), and the signature lets a server verify the token hasn't been tampered with.

Each segment is Base64url-encoded JSON โ€” not standard Base64, so it uses -/_ instead of +//and typically drops padding, which is why pasting a raw JWT segment into a general Base64 decoder often fails. The payload's registered claims (RFC 7519 ยง4.1) include iss (issuer), sub (subject), aud (audience), and exp (expiration, a Unix timestamp) โ€” decoding eyJzdWIiOiIxMjM0NTY3ODkwIn0 reveals {"sub":"1234567890"}, for instance. Because decoding only reverses the encoding, this tool cannot tell you whether a token is genuine โ€” verifying the signature requires the issuer's secret or public key, which never leaves their server.

  • Inspect an access or ID token from an OAuth/OIDC provider to confirm claims like exp, aud, or a custom role claim without writing code
  • Debug why an API rejects a token โ€” for example checking the exp timestamp for expiry or the alg in the header
  • Learn JWT structure by decoding sample tokens before integrating a JWT library

Also try the JSON formatter, JSON validator, JSON minifier, or JSON viewer.

JWT Decoder FAQ

Does this tool verify the JWT signature?
No. It decodes the header and payload only. Verifying a signature requires the issuer's secret or public key, which this browser-only tool never has access to.
Why does decoding fail with an error?
A JWT needs at least two dot-separated segments (header and payload). Extra whitespace, a truncated token, or a non-JWT string pasted in will fail to decode.
What's the difference between the header and payload?
The header names the signing algorithm and token type (e.g. HS256, JWT). The payload carries the actual claims โ€” data such as subject, issuer, and expiration.
Is it safe to decode a real token here?
Decoding happens entirely in your browser and the token is never sent anywhere. Still, treat tokens from production systems carefully โ€” anyone holding the raw token can read its payload.