JWT Decoder

Decode and inspect a JWT without sending it anywhere.

Input
JWT input
Output
Result
Options

Spaces per level of nesting.

Further reading

  • How to decode a JWTDecode a JSON Web Token safely: the three segments, what each claim means, why decoding is not verification, and the expiry and algorithm pitfalls.

About this tool


A JSON Web Token is three Base64url segments joined by dots: a header naming the signing algorithm, a payload of claims, and a signature. The first two are merely encoded, not encrypted, so anyone holding the token can read them, which is exactly what this tool does.

That a token is decodable by anyone is the single most important thing to understand about JWTs. Never put anything confidential in a payload. This decoder also surfaces the standard time claims in readable form and tells you immediately whether a token has expired, which is usually the actual question.

Because tokens are credentials, this runs entirely in your browser. Pasting a production token into a server-side decoder means handing a live credential to a third party. This tool never transmits it.

How to use it

  1. Paste or upload your jwtDrop a file onto the input pane, use the file picker, or paste the text directly.
  2. Adjust the options if neededThe defaults suit most input; open Options to change the behaviour.
  3. DecodePress Decode, or use Ctrl+Enter (Cmd+Enter on macOS).
  4. Copy or downloadCopy the result, or download it as a .json file.

Worked examples


Each example below is executed against this tool by the test suite, so what you see is what the tool actually produces.

A standard HS256 token

Input

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjMiLCJuYW1lIjoiSm9obiIsImlhdCI6MTUxNjIzOTAyMn0.sig

Output

// Header
{
  "alg": "HS256",
  "typ": "JWT"
}

// Payload
{
  "sub": "123",
  "name": "John",
  "iat": 1516239022
}

// Claims
alg: HS256
Issued at (iat): 2018-01-18T01:30:22.000Z
sub: 123

The header and payload decode from Base64url; the iat timestamp is rendered as a date.

What to watch for


The details that decide whether a conversion is correct, and where information can be lost without any error being raised.

The signature is not verified, and cannot be
Verification needs the signing key, which only the issuer has. This tool decodes and displays; it does not validate. A decoded token proves nothing about authenticity, anyone can craft a token with any payload. Always verify server-side against the issuer's key before trusting a claim.
Base64url, not Base64
JWT segments use the URL-safe alphabet, with - and _ replacing + and /, and the padding stripped. That is why pasting a whole JWT into a standard Base64 decoder fails: the dots are not valid Base64, and the alphabet differs.
The time claims that matter
exp is the expiry, nbf the not-before time, and iat when the token was issued. All three are Unix timestamps in seconds, not milliseconds, and each is shown here as an ISO 8601 date, with exp explicitly flagged as expired or still valid. A "token invalid" error in an application is very often simply an expired exp.
The alg: none attack
If a header declares "alg": "none", the token is unsigned. Some older libraries accepted such tokens as valid, letting an attacker forge any payload by simply removing the signature. The algorithm is highlighted here for exactly that reason. A related attack switches RS256 to HS256 so the public key gets used as an HMAC secret, always pin the expected algorithm server-side rather than trusting the header.
JWE tokens cannot be read
A token with five segments rather than three is a JWE, encrypted rather than merely signed. Its payload is genuinely unreadable without the decryption key, so the tool reports this instead of failing obscurely.

Limitations


  • Decodes only; signature verification requires the issuer's key.
  • Encrypted JWE tokens cannot be decoded.
  • Processing happens in your browser, so very large inputs are bounded by available memory. Files above roughly 10 MB are handled but will feel slower, and multi-hundred-megabyte files are better suited to a command-line tool.

Questions


Is my token sent to a server?
No, and that is deliberate, a JWT is a live credential. Decoding happens in your browser and you can verify it in the Network tab: no request carries your token or the decoded output.
Can this tell me whether a token is valid?
It can tell you whether the token has expired and what it claims, but not whether the signature is genuine. That needs the issuer's key. Verify signatures server-side.
Why can anyone read my JWT payload?
Because JWTs are signed, not encrypted. Base64url is an encoding, so the payload is public to anyone holding the token. Never put secrets in it; use a JWE if you need confidentiality.
Why does my five-segment token fail?
That is a JWE, an encrypted token. Without the decryption key its payload cannot be read by any tool.