JWT Decoder
Decode a JWT header and payload so you can see claims such as issuer, audience, expiry, subject, and scopes. It is for inspection and debugging, not for trusting a token. It is free, needs no account, and adds no watermark to your result.
Loading text tools…
Working with other formats? Open your file workspace →
What people use it for.
What happens to your file.
The token is split into header, payload, and signature. The first two parts are Base64URL-decoded and printed as JSON, while time-based claims are converted to readable dates.
Where it stops: Decoding is not verification. A token can be forged unless the signature is checked with the issuer public key, which this utility does not do.
Everything you need, without a paywall.
Common questions.
Is it safe to paste a token?
Use test tokens whenever possible. A real access token can grant access until it expires.
Does decoding verify the signature?
No. It only reads the header and payload.
What does exp mean?
It is the expiry time as a Unix timestamp, converted to a readable date in the result.
You might also need.
Encode and decode Base64, URLs and HTML entities or generate SHA-256, SHA-512, MD5, UUIDs and random strings.
Format, validate, beautify and minify JSON or convert JSON to XML, CSV and YAML using one online toolbox.
Parse a URL into protocol, hostname, port, path, query parameters, fragment and normalized URL fields.
Convert Unix seconds or milliseconds to ISO dates and convert ISO date-time strings back to Unix timestamps.