What the JWT decoder does
A JSON Web Token packs three Base64URL-encoded parts — header, payload, and
signature — separated by dots. This decoder splits the token, decodes the
header and payload to readable JSON, and surfaces the standard claims
(issuer, subject, audience, and the exp expiry) so you can see
exactly what a token asserts. It runs entirely in your browser — the token
never leaves your machine.
How to decode a JWT
- Paste the token (the
eyJ…string) into the box above. - Read the decoded header (algorithm + type) and payload (claims).
- Check the expiration status — the tool flags whether
expis in the past.
Decoding is not verifying
Anyone can decode a JWT — the payload is only encoded, not encrypted. Decoding shows what a token claims; it does not prove the token is authentic. Verification means checking the signature against the issuer's secret or public key, which happens on your server. Never trust a decoded payload as proof of identity without verifying the signature first.