JWT Decoder
Inspect JWT header, payload, and expiry without sending the token anywhere.
A JWT is three Base64URL segments separated by dots: header, payload, signature. The first two are encoded, not encrypted — anyone holding the token can read them. This decoder splits the token, formats both, and explains the standard claims including whether it has expired.
It runs in your browser on purpose. People paste live access tokens into JWT decoders, and a token that reaches someone else's server should be treated as compromised.
How to use it
- Paste the complete token, including both dots.
- Read the decoded header and payload.
- Check the claims panel for issuer, subject and expiry.
Not working as you expect? Report a problem with this tool.