Paste a JWT. Read Every Claim. Send Nothing.
Paste a JWT and its header, payload claims, and expiry appear in plain language — valid or expired at a glance, alg:none tokens flagged. Nothing leaves your browser.
JWT Decoder
Built for developers debugging auth flows and API callbacks. Decode-only: your token is split and read locally, and the signature is never verified or checked against anything. Fully client-side — no network calls, no storage.
Decoded
Header
Payload claims
| Claim | Value | Copied as |
|---|
Signature
Not verified — this tool decodes only. Signature validity is up to your own server-side check.
How to use:
- Paste a JWT (three dot-separated segments). A leading
Bearerand extra whitespace are stripped automatically - The header and payload are base64url-decoded live — claims show one per row with a copy button, standard time claims (
exp/nbf/iat) are shown in your local timezone - The badge at the top tells you at a glance whether the token is valid, expired, or not yet valid — based on your device's clock
alg:nonetokens are flagged red: unsigned JWTs are a common misconfiguration or attack vector- Use "Copy payload as JSON" to send the claims straight to the JSON Formatter
Everything runs in your browser: no network calls, no analytics on your input, nothing stored. Treat any token you paste here as a credential — that is exactly why it never leaves your device.