Decode JSON Web Tokens
A JSON Web Token (JWT) is a compact string used to pass identity and permission information between systems — most often as an Authorization: Bearer header after logging in. It looks like random text, but it is three Base64URL-encoded parts: a header, a payload of claims, and a signature. This JWT decoder splits the token, decodes the first two parts into readable JSON and explains the important claims. Decoding and verification happen locally, so your token is never transmitted.
Features
- Header and payload decoded and pretty-printed, each with a copy button.
- Time claims explained:
iat,nbf,expandauth_timeconverted from epoch seconds to dates in your time zone. - Expiry check that tells you at a glance whether the token is expired or not yet active.
- HMAC signature verification for HS256, HS384 and HS512 using your browser's Web Crypto API.
- Works offline after the page loads; no data is sent anywhere.
When to use it
Debugging authentication. When a request fails with 401 Unauthorized, decode the token to check whether it has expired, was issued for the right audience (aud) or carries the expected roles and scopes.
Building and testing APIs. Verify that your server puts the claims you intended into the token, with correct expiration times, before you ship.
Learning how OAuth and OpenID Connect work. ID tokens and access tokens from identity providers are often JWTs. Decoding a test token shows what information the provider shares about a user.
Anatomy of a JWT
header.payload.signature
- Header — the token type and signing algorithm, for example
{"alg":"HS256","typ":"JWT"}. - Payload — the claims. Registered claims include
iss(issuer),sub(subject, usually the user ID),aud(audience),exp,nbf,iatandjti(token ID). Apps add custom claims such asnameorrole. - Signature — created by signing
header.payloadwith a secret (HMAC) or a private key (RSA, ECDSA, EdDSA). If anyone changes even one character of the header or payload, the signature no longer matches.
Because the payload is only encoded, never put secrets such as passwords into a JWT. To decode other Base64 data, use the Base64 tool; to inspect any timestamp, use the Unix Timestamp Converter.