JWT Decoder

Decode the header, payload, and signature of a JSON Web Token. Decoding is local — your token is never sent to a server.

Decoded locally — token never leaves your browserNo upload, no signup

JWT

0 lines · 0 chars

Decoded

0 lines · 0 bytes
Decoding is not verification.Anyone can decode a JWT — the signature is what proves authenticity. Verify signatures on the server.

Understanding JWT structure.

A JSON Web Token (JWT) consists of three parts separated by dots: header.payload.signature. Each part is base64url-encoded independently. The header specifies the signing algorithm (such as HS256 or RS256) and the token type. The payload carries the claims — statements about the entity (typically a user) and additional metadata. The signature is created by encoding the header and payload with a secret key, which allows recipients to verify the token was not tampered with.

Because each segment is only base64url-encoded (not encrypted), anyone can decode a JWT to read its contents. The security of a JWT relies entirely on the signature: a valid signature proves the issuer holds the secret key and that the payload has not been modified. Never store sensitive data in a JWT payload without additional encryption.

Common JWT claims.

The JWT specification defines several registered claims. The exp claim is a Unix timestamp indicating when the token expires. The iat (issued at) claim records when the token was created. The sub (subject) claim identifies the principal — usually a user ID. The iss (issuer) claim identifies who created the token. The aud (audience) claim specifies the intended recipient. The nbf (not before) claim marks the earliest time the token is valid. The jti (JWT ID) claim provides a unique identifier for the token.

Custom claims can carry any application-specific data. A common pattern is embedding user roles, permissions, or profile information directly in the payload so the server can authorise requests without additional database lookups.

Use cases for JWT.

JWTs are widely used for stateless authentication in web and mobile applications. After a user logs in, the server issues a signed JWT. The client includes the token in the Authorization header of subsequent requests. The server verifies the signature and extracts claims without storing session state.

JWTs also power single sign-on (SSO) flows, API gateway authorisation, and microservice-to-microservice authentication. Because they are self-contained, JWTs eliminate the need for shared session storage across distributed services.

Security considerations.

Always verify the JWT signature on the server before trusting any claims. Decoding is not the same as verification — a decoded token can still be forged or expired. Use short expiration times for access tokens and rotate signing keys regularly. Avoid the none algorithm, which disables signature verification entirely. Store tokens in HTTP-only cookies rather than localStorage to reduce exposure to cross-site scripting attacks.

Debugging with decoded tokens.

When authentication fails, decoding the token reveals whether the issue is an expired token, wrong audience, missing issuer, or incorrect subject. Check the exp claim against the current time, verify the iss claim matches your identity provider, and confirm the aud claim includes your API identifier. If any of these are missing or mismatched, the token was likely issued for a different environment or purpose.

The decoded header also shows the algorithm used for signing. If you expect RS256 but see HS256, an attacker may be trying to downgrade the algorithm. Always enforce expected algorithms on the server side. This decoder makes it easy to spot these issues before they cause problems in production.

Your input is processed locally and isn't uploaded for processing. Verify by opening DevTools → Network — there are no requests carrying your data.

JWT Decoder examples.

// Paste a JWT to decode

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkphbmUgRG9lIiwiaWF0IjoxNzA1MzEwOTAwLCJleHAiOjE5OTk5OTk5OTl9.dQw4w9WgXcQ

Frequently asked questions.

What is a JWT decoder?

A JWT decoder reads the header and payload of a JSON Web Token (JWT) and displays them in readable JSON format. It uses base64url decoding — no secret key needed. The signature is shown but not verified.

What is the best JWT decoder online?

This free online JWT decoder runs entirely in your browser with no token upload. It shows the header, payload, expiration status, and registered claims instantly. For server-side verification, use libraries like jsonwebtoken (Node.js) or PyJWT (Python).

How to decode a JWT token?

Paste your JWT (header.payload.signature format) into the input panel. The decoded header and payload appear instantly, along with metadata like issuer, subject, and expiration status.

How to decode JWT in Python?

Use PyJWT: import jwt; decoded = jwt.decode(token, options={"verify_signature": False}). For server verification: jwt.decode(token, secret, algorithms=["HS256"]). Our online tool works without any installation.

How to decode JWT in JavaScript?

Use atob() to decode base64url segments: const payload = JSON.parse(atob(token.split(".")[1])). For Node.js, use the jsonwebtoken library. Our online tool does this automatically.

How to decode JWT in Spring Boot?

Use the JJWT library: Jwts.parserBuilder().setSigningKey(key).build().parseSignedClaims(token).getBody(). Or paste your token into this online decoder for quick inspection.

Is decoding the same as verification?

No. Decoding only reads the header and payload — it does not check the signature or prove authenticity. Anyone can decode a JWT. Always verify signatures on the server.

Is my JWT data sent to a server?

No. Decoding runs entirely in your browser using JavaScript. Your token never leaves your device. However, do not paste tokens you do not own into third-party services.

What are JWT registered claims?

The JWT spec defines standard claims: iss (issuer), sub (subject), aud (audience), exp (expiration timestamp), nbf (not before), iat (issued at), and jti (token ID).

How do I read JWT expiration?

The exp claim is a Unix timestamp in seconds. This decoder computes the expiration date and shows whether the token is expired or fresh. If no exp claim exists, expiration is not set.

What is the difference between JWT decoder and encoder?

A decoder reads and displays JWT contents (header, payload, signature). An encoder creates JWTs by signing a payload with a secret key. This tool decodes only — encoding requires your own secret.

How does JWT decoding work?

JWTs have three base64url-encoded segments separated by dots. Decoding splits the token, base64url-decodes the header and payload, and parses them as JSON. The signature is displayed but not verified.

Related tools.