JWT Decoder
Decode a JSON Web Token to see its header, its claims and exactly when it expires — in your browser, so the token is never transmitted.
What it does
JWT Decoder applies the encoding exactly as specified, including the edge cases that hand-rolled versions get wrong: Unicode beyond ASCII, padding, reserved characters, and the difference between encoding a whole URL and encoding one component of it.
When you need it
Embedding data somewhere that only accepts plain text — a query string, a header, a data URI, a config value — or reading back a string that arrived already encoded and needs to be legible.
Limits and caveats
Encoding is not encryption and offers no protection whatsoever: anyone can decode it in a second. Do not use it to hide credentials or anything else that matters. Everything happens in your browser, so the file never leaves your device.
How to use the JWT Decoder
- Paste the token. A leading “Bearer ” is fine, we strip it.
- Read the claims, with exp and iat shown as real dates.
- Nothing is sent anywhere — check your network tab if you like.
Frequently asked questions
- Does this verify the signature?
- No, and no honest online tool should. Verifying needs the issuer's secret or private key, and pasting that into a website hands over the power to mint tokens. Decoding is a different thing: it only reads what's already inside the token.
- Is it safe to paste a real token here?
- Safer than anywhere that sends it to a server, because this page never does — the decoding is JavaScript running on your machine. A token is still a live credential though, so treat it like a password wherever else it goes.
- Why does it say expired when my API accepts it?
- The exp claim is compared against your computer's clock. If your clock is wrong, or the server allows a leeway window, the two can disagree.
- Do my files get uploaded?
- No. This tool runs entirely in your browser, so the file never leaves your device.