home / tools / jwt decoder

JWT Decoder.

Paste a JSON Web Token. The header, payload, and signature decode live as you type. Standard claims are labeled and expiry is flagged. Token never leaves your browser, so it's safe for production data.

// how it works

JWTs are three base64url-encoded segments separated by dots: header.payload.signature. This tool splits on the dots, base64url-decodes the first two segments, parses them as JSON, and renders them as formatted text. The signature is shown as-is; verifying it would require the issuer's secret or public key.

Everything runs in your browser via a small jwt-decoder.js file. Nothing is sent to a server. You can confirm by viewing the source of this page or watching the network tab in DevTools while you paste a token.

Because the decoding happens locally, you can use this with whatever tokens you'd otherwise be hesitant to paste into a third-party web form: internal service tokens, prod tokens covered by company policy, anything under NDA.

What this tool does NOT do:

  • Signature verification: verifying a signature requires the secret (HS256) or public key (RS256/ES256). Verify in your application code or via a CLI tool you trust with secrets.
  • Editing / re-signing: same reason. Use a JWT library in your language of choice (e.g. jose, PyJWT).

What it DOES do: decode header, decode payload, show the signature as base64url (so you can compare it to expected), label standard claims (iss, sub, aud, exp, etc.) with human-readable names, convert exp/nbf/iat timestamps to ISO time + relative ("3 days ago"), and flag whether the token is expired.

Related: need to base64-encode arbitrary text or files instead? The Base64 Encoder & Decoder handles UTF-8 text plus file-to-base64 with data-URL output.

// a free, browser-only tool by Tiempo Software, built in Omaha, Nebraska. Runs entirely in your browser; nothing you enter is uploaded. see all tools.