JWT Decoder

Decode a JSON Web Token's header and payload locally — Base64url segments are decoded in your browser and exp/iat timestamps are shown as readable dates. The signature is never verified or sent anywhere.

Loading calculator…

What this tool does

Decode a JSON Web Token's header and payload locally — Base64url segments are decoded in your browser and exp/iat timestamps are shown as readable dates. The signature is never verified or sent anywhere. Decoding is not verification: this tool never checks the signature, so a decoded payload proves nothing about authenticity. Tokens are capped at 10,000 characters and never leave the device.

How to use the JWT Decoder

  1. Enter or select json web token.
  2. Read the calculated result; change any measurement to compare alternatives.

Formula

Split the token on '.'; Base64url-decode segment 1 (header) and segment 2 (payload) as UTF-8 JSON; exp/iat are Unix seconds converted to UTC dates.
token
JSON Web Token

Decoding is not verification: this tool never checks the signature, so a decoded payload proves nothing about authenticity. Tokens are capped at 10,000 characters and never leave the device.

Worked example

For jwt decoder, the following measurements illustrate the exact method: JSON Web Token: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6Ik1hc3RlclRvb2wgVXNlciIsImlhdCI6MTc1OTc0MTIwMCwiZXhwIjoxODkzNDU2MDAwfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c.

Inputs

  • JSON Web TokeneyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6Ik1hc3RlclRvb2wgVXNlciIsImlhdCI6MTc1OTc0MTIwMCwiZXhwIjoxODkzNDU2MDAwfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c

Result

  • Header (JSON){ "alg": "HS256", "typ": "JWT" }
  • Payload (JSON){ "sub": "1234567890", "name": "MasterTool User", "iat": 1759741200, "exp": 1893456000 }
  • Signature presentYes (not verified)
  • Algorithm (alg)HS256
  • Expires (exp)2030-01-01T00:00:00.000Z (1893456000 Unix seconds)
  • Issued at (iat)2025-10-06T09:00:00.000Z (1759741200 Unix seconds)

Results explained

Header (JSON)
Header (JSON) from the formula above. Decoding is not verification: this tool never checks the signature, so a decoded payload proves nothing about authenticity. Tokens are capped at 10,000 characters and never leave the device.
Payload (JSON)
Payload (JSON) from the formula above. Decoding is not verification: this tool never checks the signature, so a decoded payload proves nothing about authenticity. Tokens are capped at 10,000 characters and never leave the device.
Signature present
Signature present from the formula above. Decoding is not verification: this tool never checks the signature, so a decoded payload proves nothing about authenticity. Tokens are capped at 10,000 characters and never leave the device.
Algorithm (alg)
Algorithm (alg) from the formula above. Decoding is not verification: this tool never checks the signature, so a decoded payload proves nothing about authenticity. Tokens are capped at 10,000 characters and never leave the device.
Expires (exp)
Expires (exp) from the formula above. Decoding is not verification: this tool never checks the signature, so a decoded payload proves nothing about authenticity. Tokens are capped at 10,000 characters and never leave the device.
Issued at (iat)
Issued at (iat) from the formula above. Decoding is not verification: this tool never checks the signature, so a decoded payload proves nothing about authenticity. Tokens are capped at 10,000 characters and never leave the device.

Frequently asked questions

No. Anyone can create or edit an unsigned-looking payload. Decoding only reads the Base64url-encoded JSON; verification requires the issuer's key and checks the signature, which this local tool deliberately does not do.

exp is the expiry time and iat the issued-at time, both Unix seconds. sub is the subject (usually a user ID). This tool shows exp and iat as UTC dates as well as raw seconds.

The token is decoded entirely in your browser with no network request. Even so, treat live access tokens as secrets and avoid pasting production tokens into any tool out of habit.

A JWT needs exactly three dot-separated Base64url segments, and the first two must be valid JSON. Tokens with whitespace, a missing segment, or non-JSON payloads are rejected with an error.

A URL-safe variant of Base64 that uses '-' and '_' instead of '+' and '/' and usually omits '=' padding. JWTs use it so tokens survive URLs and headers unchanged.