Free online JWT decoder. Inspect header and payload claims, check token expiration. No signup, runs locally in your browser. 100% free and private.
A JSON Web Token (JWT) is a compact, URL-safe token format used for securely transmitting information between parties. JWTs are widely used for authentication (login sessions), authorization (access control), and information exchange in modern web applications and APIs.
A JWT consists of three parts separated by dots: header.payload.signature. The header specifies the algorithm used for signing. The payload contains the claims (data). The signature verifies that the token hasn't been tampered with.
The header and payload are Base64url-encoded JSON strings. Decoding them is straightforward: replace URL-safe characters (- with +, _ with /), add padding, then Base64-decode and parse the resulting JSON. This tool performs exactly this process.
Important: decoding is not the same as verification. Anyone can decode a JWT — the payload is not encrypted. The signature exists to prevent tampering, not to hide the contents.
JWTs are signed, not encrypted. Anyone who intercepts a JWT can read its contents. Never store sensitive data (passwords, credit card numbers) in JWT payloads. Use HTTPS to protect tokens in transit. Set short expiration times and implement token refresh mechanisms.
The header's alg field specifies the signing algorithm. Common algorithms include:
This tool checks the exp claim and tells you whether the token has expired. Expired tokens should be rejected by the server. If your token is expired, you typically need to re-authenticate or use a refresh token to obtain a new one.
All decoding happens in your browser. Your JWT tokens are never sent to any server. However, be aware that JWTs may contain personally identifiable information — handle them carefully.
Generate HMAC signatures with our HMAC Generator. Encode data with our Base64 Encoder. Validate JSON payloads with our JSON Validator.
No. This tool only decodes (reads) the header and payload. Signature verification requires the secret key or public key and should be done server-side.
Yes. Decoding happens entirely in your browser. The token is never sent to any server. However, if the JWT contains sensitive data, be cautious about where you paste it.
Claims are the key-value pairs in the payload. Standard claims include sub (subject), iat (issued at), exp (expiration), iss (issuer), and aud (audience). Custom claims can contain any application-specific data.
A JWT has three base64url-encoded parts separated by dots: Header (algorithm and type), Payload (claims/data), and Signature (verification hash). This tool decodes the first two.
No. Modifying the payload would invalidate the signature. JWTs are designed to be tamper-proof — any change requires re-signing with the secret key.
Browse all free tools · Guides and tutorials · PDF tools · Developer tools · Text tools · SEO tools