Logics Guru

JWT Decoder

Inspect JWT header, payload, and expiry without sending the token anywhere.

Runs entirely in your browser. Your data never leaves this device and is never sent to our servers.
Header
Payload
Standard claims

A JWT is three Base64URL segments separated by dots: header, payload, signature. The first two are encoded, not encrypted — anyone holding the token can read them. This decoder splits the token, formats both, and explains the standard claims including whether it has expired.

It runs in your browser on purpose. People paste live access tokens into JWT decoders, and a token that reaches someone else's server should be treated as compromised.

How to use it

  1. Paste the complete token, including both dots.
  2. Read the decoded header and payload.
  3. Check the claims panel for issuer, subject and expiry.

Not working as you expect? Report a problem with this tool.

Frequently asked questions

Is my token sent to your server?
No. Decoding happens in your browser and no request is made. You can confirm it in your network tab — there is no request when you decode.
Does this verify the signature?
No. Verifying requires the secret or public key, and sending us your signing key would be far worse than sending the token. Verify in your application, where the key already lives.
Why can anyone read my payload?
Because a JWT payload is encoded, not encrypted. Never put anything confidential in it — the signature proves it has not been altered, it does not hide anything.
What do iat, nbf and exp mean?
Issued-at, not-before, and expiry, all as Unix timestamps. The claims panel converts them to readable dates and flags expired tokens.