AI Tools Free

JWT Decoder

Inspect a compact JSON Web Token by decoding its header and payload locally. Read unverified claims and supported time values in UTC; the signature is not checked.

Free to useNo sign-upRuns in your browser
Enter your details

Enter the inputs, then select Decode JWT.

Your result
Enter your details

Result will appear here

How JWT Decoder works

The decoder reads the first two Base64url segments as UTF-8 JSON and displays the declared header algorithm and payload without verifying the signature.

Supported exp, iat, and nbf NumericDate claims are also shown in UTC. The signature is not verified, so decoded content must not be used as an authentication or authorization decision.

Remove an accidental Bearer prefix and check the number of dot separated parts.

A compact JWT connected to separate header and payload document panels.
Illustration of the JWT Decoder workflow.

How to use JWT Decoder

Paste a compact three part JWT to inspect its header and payload locally.

Enter one compact JWT

Paste the complete three-part token into JWT. Keep the segments and separators intact. This form is for compact JWT inspection, rather than an encrypted token or a separate Base64 text value.

JWT
JWT Decoder native input panel with the actual JWT settings used for this example.
Configure JWT; select Decode JWT.

Decode the unverified content

Run the decoder and read the Unverified result. The panel displays header and payload JSON, the declared header algorithm, and supported NumericDate claims in UTC.

Unverified
JWT Decoder actual result panel showing Unverified.
Submitted result: Unverified. Header algorithm: none.

Review claims without treating them as proof

Read the Signature: Not verified status and the authentication warning. Copy or download the decoded text only for inspection. A trusted verifier must separately check signature, issuer, audience, and other requirements.

Output and export
JWT Decoder actual output and export region and result note after submitting the pictured settings.
Review the actual JWT Decoder output and visible Copy result, Download decoded-jwt.txt controls. Read the result note.

When to use JWT Decoder

Decoded claims can support debugging when their unverified status remains explicit.

Investigate a token field

Decode a test token when checking which claim names an integration places in the payload. Compare that structure with the receiving application requirements. The result can reveal a missing or differently named field but cannot establish that authentication should succeed.

Developer input and configuration represented by document cards.
Prepare the input. Concept illustration.

Inspect JWT expiry and issue-time claims

Read a supported expiry or issue time when investigating a test session problem. Confirm the actual validation behavior in the application separately. A visible date does not prove that the signature, audience, issuer, or token lifetime was accepted.

A developer example flowing from input to reviewed output.
Inspect an example. Concept illustration.

Document a claim structure

Use a suitable nonsecret example to describe a token payload in technical notes. Include the meaning of each relevant field from the integration documentation. Avoid presenting the decoded example as proof that a real account has those permissions.

Developer output handed to the next stage of a workflow.
Use the result in your workflow. Concept illustration.

Decode JWT claims without verifying the signature

Use the decoded header and claims for inspection while keeping trust decisions separate from readable token content.

The signature is not cryptographically verified. The decoder can accept an alg none header with an empty third segment, so successful decoding is especially unsuitable as an authorization decision.

A five part encrypted JWE is outside this compact JWT decoder. Textual structure checks do not decrypt a token, validate a signing key, or establish trust in its claims.

A developer result reviewed alongside its source.
Review the returned output. Concept illustration.

Check token format errors

Check the compact token structure and the application’s verification process before relying on a claim.

Remove an accidental Bearer prefix and check the number of dot separated parts. Malformed Base64URL, invalid UTF-8, or header and payload values that are not JSON objects are rejected.

Non numeric time claims are shown as unsupported rather than interpreted as timestamps. Check the format used by the issuer and use a proper verifier in the consuming application when assessing validity.

Input format and assumptions reviewed for a developer task.
Check format and assumptions. Concept illustration.

Inspect a JWT header and payload

Paste a compact three part JWT to inspect its header and payload locally.

Inspect a JWT

JWT Decoder: common questions

Answers about using JWT Decoder and understanding its results.

Does a decoded token prove it is valid?

No. A trusted verifier must check signature, issuer, audience, and other requirements.

Does the header algorithm prove how the token was signed?

No. It is a decoded claim from the token. A trusted verifier must decide and verify the allowed algorithm.

How are time claims shown?

Supported numeric exp, iat, and nbf claims are interpreted as Unix seconds and displayed in UTC. Unsupported NumericDate values are marked accordingly.

Which token format can I enter?

Use a compact three-part JWT within 100,000 characters. Header and payload segments must decode to JSON objects. Five-part encrypted JWE is outside this decoder.