JWT Decoder
Decode and inspect JWT header and payload — shows expiry status and issued-at time.
How to use this tool
- 1Paste a JWT token into the textarea (the full eyJ... string).
- 2The decoded Header and Payload appear as formatted JSON below.
- 3If the token has an exp claim, a green or red banner shows whether it is expired.
About JWT Decoder
This JWT decoder inspects header and payload as formatted JSON and shows whether an exp claim is expired. Decoding is not signature verification.
Auth bugs often hide in claims you cannot read in the raw Base64url blob. A local decode avoids pasting live tokens into unknown debugger sites.
Paste a JWT token into the textarea (the full eyJ... string). The decoded Header and Payload appear as formatted JSON below. If the token has an exp claim, a green or red banner shows whether it is expired. Processing stays in your browser.
Use it to check exp/iat on a staging token, to confirm roles in a payload, or to teach juniors that JWTs are readable. Never paste production tokens on a shared machine.
Anyone can read an unsigned payload — decode ≠ verify. Algorithm confusion attacks are out of scope here. Clear the textarea after debugging live tokens.
Spot-check the output in your destination app before you rely on a large batch.
Code examples
JavaScript
function decodeJwt(token) {
const [, payload] = token.split(".");
return JSON.parse(atob(payload.replace(/-/g, "+").replace(/_/g, "/")));
}Frequently asked questions
Different tools use different definitions and parsers, so small gaps are common. JWT Decoder applies Base64URL decoding of header.payload.signature without verifying signatures with one consistent browser-side rule set. Hidden characters, stricter syntax, or a different tokenizer usually explain the mismatch. Reduce the input to a minimal sample, then add pieces back until the difference appears. Match the rule your destination actually enforces.
Treat the error as a signal that this environment is stricter or configured differently. Browser APIs reject malformed structures early instead of guessing. Convert to a boring intermediate when it helps—plain UTF-8 text, PNG, WAV, or an unlocked PDF—then retry. If the intermediate works, the original encoding was the problem. Keep that minimal sample for the next regression check.
Runtimes disagree even when feature names match. Locales, parser strictness, codec builds, and library versions differ between your browser and CI. Export the exact bytes from JWT Decoder, hash them, and compare in the pipeline. Align normalization steps so both systems see the same input. Use the browser result as a reference artifact, then make CI match it.
Desktop apps win on deep feature sets, batch farms, and specialized hardware paths. JWT Decoder wins on zero install, private local processing, and speed for the everyday job on this page. Choose desktop software for multi-hour editorial work or exotic edge formats. Choose this tool when you need a correct result quickly without uploading. Many people do a quick pass here first, then open the heavy suite only if an edge case demands it.
Prefer JWT Decoder whenever the input is personal, unpublished, customer-owned, or under NDA, because the core transform stays in your browser via Base64URL decoding of header.payload.signature without verifying signatures. Cloud services can still help for formats your browser truly cannot decode, but you must trust their retention policy. Strip secrets before any upload. Privacy is usually the reason to stay local—not a longer marketing checklist.
Start from the best original input you still have. Change only what the destination requires. Prefer lossless intermediates when you must convert twice. Because the tool is local, iterate in small steps: tweak one setting, re-run, compare. Spot-check a short sample before batching anything important.
No account is required for normal use. The core jwt decoder transform runs in your browser on your device using Base64URL decoding of header.payload.signature without verifying signatures. You get on-screen output, a copy action, or a download without a mandatory ToolBrigade upload for that step. Keep your browser updated. A few lookup utilities may call public reference APIs for live fields only—they still do not need your private documents.
Lighter text, code, calculator, and many image jobs work on modern phones. Large video encodes and huge PDFs are happier on a plugged-in laptop with more RAM. Fully client-side flows can continue offline once scripts are cached; live lookups still need network. If a run seems stuck, try a smaller sample, free memory by closing tabs, and confirm the input is not truncated. Prove the path on a short fixture before blaming the algorithm.