Skip to content
Security

JWT Decoder

Decode JWT header and payload locally. Does not verify signatures.

Decode JWTs for debugging

A JWT has three Base64URL segments: header, payload, and signature. This JWT decoder can decode the JWT header and payload as JSON and show JWT expiration from exp, plus iat and nbf when those claims exist. For a check focused on those times, use the JWT Expiration Checker. For easier reading, paste decoded JSON into the JSON Formatter. The alg value in the header is displayed with the rest of the header. It is not proof that the token is authentic.

The signature is not verified. A readable token, including one that has not expired, can still be forged. Paste the token itself; a Bearer prefix is not removed. You can decode JWT locally in the browser, then verify the signature on your server before trusting any claim.

Common questions

Does decoding a JWT verify it?

No. Decoding only turns the header and payload into readable JSON. It does not prove who issued the token.

What are the three JWT parts?

Header, payload, and signature, separated by dots and encoded as Base64URL. This tool decodes the header and payload. It does not check the signature.

Does this tool verify the signature?

No. The signature has to be present so the token has three segments, and it is not validated.

Does an unexpired JWT mean it is authentic?

No. An exp time in the future only means that claim has not passed. Anyone can write it. Trust the token only after your server verifies the signature.