JWT Decoder — Decode JSON Web Tokens Online Free

Free online JWT decoder. Inspect header and payload claims, check token expiration. No signup, runs locally in your browser. 100% free and private.

How to use

  1. Paste JWT — Paste a JWT token (the long string with two dots)
  2. Click Decode — The tool splits the token and decodes the header and payload
  3. Inspect — Review the decoded header (algorithm) and payload (claims) as formatted JSON

What Is a JWT?

A JSON Web Token (JWT) is a compact, URL-safe token format used for securely transmitting information between parties. JWTs are widely used for authentication (login sessions), authorization (access control), and information exchange in modern web applications and APIs.

A JWT consists of three parts separated by dots: header.payload.signature. The header specifies the algorithm used for signing. The payload contains the claims (data). The signature verifies that the token hasn't been tampered with.

How JWT Decoding Works

The header and payload are Base64url-encoded JSON strings. Decoding them is straightforward: replace URL-safe characters (- with +, _ with /), add padding, then Base64-decode and parse the resulting JSON. This tool performs exactly this process.

Important: decoding is not the same as verification. Anyone can decode a JWT — the payload is not encrypted. The signature exists to prevent tampering, not to hide the contents.

Common JWT Claims

  • sub (Subject): The user or entity the token represents, usually a user ID
  • iat (Issued At): Unix timestamp of when the token was created
  • exp (Expiration): Unix timestamp after which the token is invalid
  • iss (Issuer): Who created and signed the token
  • aud (Audience): The intended recipient of the token
  • jti (JWT ID): Unique identifier for the token

JWT Security Considerations

JWTs are signed, not encrypted. Anyone who intercepts a JWT can read its contents. Never store sensitive data (passwords, credit card numbers) in JWT payloads. Use HTTPS to protect tokens in transit. Set short expiration times and implement token refresh mechanisms.

JWT Algorithms

The header's alg field specifies the signing algorithm. Common algorithms include:

  • HS256: HMAC with SHA-256 (symmetric — same key signs and verifies)
  • RS256: RSA with SHA-256 (asymmetric — private key signs, public key verifies)
  • ES256: ECDSA with SHA-256 (asymmetric, smaller keys than RSA)

Token Expiration

This tool checks the exp claim and tells you whether the token has expired. Expired tokens should be rejected by the server. If your token is expired, you typically need to re-authenticate or use a refresh token to obtain a new one.

Privacy

All decoding happens in your browser. Your JWT tokens are never sent to any server. However, be aware that JWTs may contain personally identifiable information — handle them carefully.

Generate HMAC signatures with our HMAC Generator. Encode data with our Base64 Encoder. Validate JSON payloads with our JSON Validator.

Frequently asked questions

Does this verify JWT signatures?

No. This tool only decodes (reads) the header and payload. Signature verification requires the secret key or public key and should be done server-side.

Is it safe to paste JWTs here?

Yes. Decoding happens entirely in your browser. The token is never sent to any server. However, if the JWT contains sensitive data, be cautious about where you paste it.

What are JWT claims?

Claims are the key-value pairs in the payload. Standard claims include sub (subject), iat (issued at), exp (expiration), iss (issuer), and aud (audience). Custom claims can contain any application-specific data.

Why are there three parts?

A JWT has three base64url-encoded parts separated by dots: Header (algorithm and type), Payload (claims/data), and Signature (verification hash). This tool decodes the first two.

Can I edit and re-encode a JWT?

No. Modifying the payload would invalidate the signature. JWTs are designed to be tamper-proof — any change requires re-signing with the secret key.

Related free tools

  • XML Formatter & Minifier — Beautify or minify any XML — SOAP, RSS, SVG, sitemap. Browser-based parser.
  • XML to JSON Converter — Parse any well-formed XML into a clean JSON tree with attributes and arrays.
  • JSON to XML Converter — Convert JSON to well-formed XML — supports attributes, custom root, declaration.
  • CSV Viewer — Open CSV or TSV files in your browser — sort, search, paginate, export filtered view.
  • JSON to CSV Converter — Convert JSON data to CSV format. Export to spreadsheets easily.
  • CSV to JSON Converter — Convert CSV data to JSON format. Useful for API development.
  • JSON Formatter — Format, beautify, or minify JSON with customizable indentation.
  • JSON Validator — Validate JSON syntax and find errors with line and column numbers.
  • HTML Minifier — Compress HTML by removing comments, whitespace, and line breaks.
  • CSS Minifier — Minify CSS by stripping comments, whitespace, and unnecessary characters.
  • JavaScript Minifier — Compress JavaScript by removing comments, whitespace, and empty lines.
  • Base64 Encoder/Decoder — Encode text to Base64 or decode Base64 back to text. UTF-8 support.

Browse all free tools · Guides and tutorials · PDF tools · Developer tools · Text tools · SEO tools