JWT Decoder

Decode the header and payload of a JSON Web Token to inspect its claims. Runs in your browser — token secrets stay on your device.

Conversions
Decode

About JWT Decoder

JWT Decoder splits a JSON Web Token into its three parts — header, payload, and signature — and decodes the two Base64URL parts into their JSON content so you can read the algorithm, expiry, subject, issuer, and custom claims. Use it to inspect a token a server sent back, debug why a token expired, or verify the claims before sending a request. The decode is local via browser Base64URL decode — your tokens (and any claims carrying user IDs or email addresses) never leave your browser.

Best for

  • Inspecting an authentication token before adding it to a curl request
  • Debugging why an API token expired — checking exp and iat claims
  • Verifying the algorithm and issuer match what your backend expects

Pros

  • +Splits header.payload.signature and decodes header and payload to JSON
  • +Shows exp, iat, nbf in your local time, so expiry is obvious
  • +Local Base64URL decode — tokens with PII stay on your device

Cons

  • −Decode only; signature verification requires the server's public key or HMAC secret
  • −Doesn't refresh or mint tokens — read-only to inspect claims

How to use JWT Decoder

  1. 1

    Select or upload the source files from your local device storage.

  2. 2

    Specify conversion settings, options, or target output formats.

  3. 3

    Wait for the client-side browser logic to process the files securely.

  4. 4

    Download the finalized outputs directly to your system.

Frequently Asked Questions

Is decoding a JWT safe? Doesn't it require the secret?
No. The JWT header and payload are Base64URL — not encrypted — so decoding needs only the public format. Only signature verification (proving it wasn't tampered with) requires the HMAC secret or public key.
How can I tell if a token is expired?
The payload includes an 'exp' claim — a Unix timestamp in seconds. Compare it with the current time; the tool shows the exp value in human-readable form so expiry jumps out immediately.
Why does the signature show as a long base64 string?
That's the raw bytes of the HMAC or digital signature. The tool does not verify it; to verify you'd run it against the HMAC secret or public key in your backend code.
Does this work with opaque tokens (random tokens without JWT structure)?
No. Only tokens following RFC 7519 (three Base64URL parts separated by dots) decode as JWT. Opaque tokens (random bearer strings) have no JWT structure to decode; use the token's vendor documentation.
Are my JWTs uploaded during decode?
Never. Decoding runs entirely in your browser via atob plus base64url replacement. Tokens containing user IDs, email addresses, or other PII stay on your device.

Related tools

FREE

100% Free

No hidden fees, no subscriptions, and no limits. Enjoy complete access to all features gratis.

SIGNUP

No Signup Required

Start converting immediately without creating an account or sharing email address.

PRIVACY

Private & Secure

Your files never leave your device. All processing is completed locally for maximum privacy.

BATCH

Batch Conversion

Convert multiple files simultaneously to save time. Fast and efficient multi-file queue.

LOCAL

Runs in Browser

Utilizes advanced client-side WebAssembly technology to process files directly inside your tab.

FORMATS

200+ Formats

Supports a wide variety of formats including images, documents, audio, video, and more.

USER REVIEWS

JWT Decoder Quality Rating

4.8
25 reviews

How was your experience? You need to convert and download at least one file to provide feedback!