Toolslay

JWT Decoder

Paste a token below and this JWT decoder splits it into its header, payload, and signature, showing the decoded claims in readable JSON.

Loading tool…

About

About JWT Decoder

A JSON Web Token is three Base64url-encoded segments joined by dots, a header, a payload, and a signature, and a jwt decoder splits those apart and decodes the first two into readable JSON. This tool lets you decode jwt strings instantly while debugging an authentication flow, without needing a library or writing a script just to peek at what's inside.

Free, no sign-up

The header typically names the signing algorithm, something like HS256 or RS256, and the token type. The payload carries the actual claims, standard ones like exp for expiration, iat for issued-at time, and sub for the subject, usually a user ID, alongside whatever custom claims the issuing server decided to include, like a role or a permission list.

Decoding a JWT and verifying it are two completely different operations, and it's worth being clear-eyed about that distinction. Decoding just reads the Base64url-encoded header and payload back into readable JSON. Verifying confirms the signature is valid and the token hasn't been tampered with, which requires the secret or public key the token was originally signed with, something a general-purpose decoder like this one doesn't have access to.

Paste your full token in and it splits into three clearly separated sections, the decoded header, the decoded payload, and the raw signature, each formatted as readable JSON where applicable so you can scan the claims without squinting at a Base64 string.

This is most useful when an API call is failing with an authentication error and you need to check whether the token's exp claim has actually passed, or whether a role or permission claim looks different than expected. Everything decodes locally in your browser, which matters since a production token is, by definition, something you don't want sitting in a server log somewhere.

FAQ

Frequently asked questions

What exactly is a JSON Web Token?

It's an open standard, defined in RFC 7519, for securely passing claims between two parties as a compact, URL-safe string. It bundles a header, a payload of claims, and a cryptographic signature into one token, commonly used for session authentication in modern web APIs.

Does decoding a JWT also verify that it's legitimate?

No, and this trips people up constantly. Decoding just reads the data inside the token. Verifying the signature requires the actual secret or public key the server used to sign it originally, which a general decoder has no way of knowing.

If someone steals my token, can they read what's inside it?

Yes, easily. The header and payload of a standard JWT are only Base64url-encoded, not encrypted, so anyone holding the token string can decode and read the claims directly. That's exactly why sensitive data like raw passwords should never be placed inside a JWT payload.

Why does my app suddenly log me out with a token error?

Most JWTs carry an exp claim, a Unix timestamp marking when the token expires. Once the server's clock passes that timestamp, the token is rejected regardless of anything else being correct, and decoding the token lets you confirm whether that's actually what's happening.

Is it safe to decode a live production token here?

Yes, decoding happens entirely through client-side JavaScript in your browser. Nothing you paste gets transmitted anywhere or logged, which matters given that a token often represents an active user session.

What are the three parts of a JWT, exactly?

The header, which names the signing algorithm and token type; the payload, which holds the actual claims like user ID and expiration; and the signature, which is what a server uses to confirm the token hasn't been altered since it was issued.