Paste a JWT. Read Every Claim. Send Nothing.

Paste a JWT and its header, payload claims, and expiry appear in plain language — valid or expired at a glance, alg:none tokens flagged. Nothing leaves your browser.

JWT Decoder

Built for developers debugging auth flows and API callbacks. Decode-only: your token is split and read locally, and the signature is never verified or checked against anything. Fully client-side — no network calls, no storage.

How to use:

  1. Paste a JWT (three dot-separated segments). A leading Bearer and extra whitespace are stripped automatically
  2. The header and payload are base64url-decoded live — claims show one per row with a copy button, standard time claims (exp/nbf/iat) are shown in your local timezone
  3. The badge at the top tells you at a glance whether the token is valid, expired, or not yet valid — based on your device's clock
  4. alg:none tokens are flagged red: unsigned JWTs are a common misconfiguration or attack vector
  5. Use "Copy payload as JSON" to send the claims straight to the JSON Formatter

Everything runs in your browser: no network calls, no analytics on your input, nothing stored. Treat any token you paste here as a credential — that is exactly why it never leaves your device.