JWT Decoder

Decode JSON Web Tokens and inspect their claims.

Decoding happens entirely in your browser, tokens are never sent or stored anywhere. Do not paste production tokens from systems you do not own.

About this tool

Debugging authentication usually starts with staring at a JWT and wondering what's inside it. This free decoder answers that instantly: paste the token and get a syntax-highlighted breakdown of the header (algorithm and type) and the payload (every claim, explained in plain English), exp and iat rendered as real dates, not Unix timestamps.

It's built for the way developers actually debug auth: checking whether a token is expired, confirming the right scopes or roles are present, or figuring out why an API rejects a token. The signature section clearly explains what can and can't be verified without your secret key, so there's no false confidence.

How to use the jwt decoder

  1. 1Paste your JWT (the three-part xxxxx.yyyyy.zzzzz string) into the input.
  2. 2The header and payload decode instantly with syntax highlighting.
  3. 3Read the claim explanations: exp, iat, iss, sub, aud, and custom claims.
  4. 4Check the signature section to see if the token is signed and whether it can be verified here.

Good to know

The privacy design matters here more than anywhere: tokens are credentials. This decoder runs 100% client-side, your token never leaves the browser tab. No server logs, no analytics exfiltration, no risk.

Frequently asked questions

A JSON Web Token is a compact, URL-safe way to represent claims between two parties. It has three Base64-encoded parts separated by dots: header, payload, and signature.

More free tools you might find useful.

Part of Developer Tools on JoliTools, free tools, no sign-up.