Skip to content
Browser tool Runs locally

JWT Decoder

Decode JWT headers and payloads locally without verifying the signature.

JWT token
Header
Decoded header will appear here.
Payload
Decoded payload will appear here.

Decoded locally in your browser. Decoding does not verify the token signature or prove the token is trustworthy.

What a JWT decoder shows

A JSON Web Token normally contains a Base64URL-encoded header and payload plus a signature. This tool decodes the readable header and payload and displays common time claims such as exp, iat, and nbf when present.

Decoding is not verification

Anyone can decode a JWT. Decoding does not prove the signature is valid, the issuer is trusted, or the claims should be accepted. Signature verification requires the correct key and algorithm in the system that consumes the token.

Frequently asked questions

Does decoding verify the JWT signature?
No. It only decodes the header and payload. Treat the contents as untrusted until the signature and claims are verified by the system using the token.
Is my token uploaded?
No. Decoding happens in your browser. Do not paste production secrets into tools you do not trust.
What are exp and iat?
exp is commonly the expiration time and iat is the issued-at time, represented as Unix timestamps when those claims are present.

Related tools