JWT Parser and Decoder Online
A JSON Web Token (JWT) is three URL-safe Base64 segments joined by dots: a header, a payload of claims, and a signature. This tool splits the token and decodes the header and payload so you can read exactly what an access or ID token carries — who issued it, who it is for, and when it expires. It is a decoder, not a validator: it does not check the signature, so a token that decodes cleanly here may still be forged or tampered with.
Because the payload is only encoded, never put secrets in a JWT — anyone holding the token can read every claim. Common claims include iss (issuer), sub (subject/user), aud (audience), exp (expiry, a Unix timestamp in seconds), iat (issued-at), and nbf (not-before).
How to use it
- Paste the full token (header.payload.signature) into the input.
- Read the decoded header to see the signing algorithm (the alg field) and token type.
- Read the decoded payload to inspect the claims — check exp against the current time to see whether the token is still valid.
- To confirm a token is authentic, verify its signature with the issuer's key in your backend; this tool does not do that.
Common use cases
- Decode a JWT to read its header and payload claims without verifying it.
- Check the expiry, issuer, and scopes carried by an access token.
- Debug an auth issue by inspecting exactly what a token contains.
Examples
Decode a JWT payload
Input eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjM0IiwibmFtZSI6IkppbSJ9.abc123
Output header: { "alg": "HS256" } payload: { "sub": "1234", "name": "Jim" }
The first two dot-separated segments are URL-safe Base64; decoding them reveals the header and claims. The signature (abc123) is left unchecked.
Frequently asked questions
- What is a JWT?
- A compact, URL-safe token of three Base64 parts — header, payload, and signature — used to carry authentication and authorization claims between services.
- Does this tool verify the signature?
- No. It only decodes the header and payload for inspection. Verifying authenticity requires the issuer's secret or public key, which you check server-side.
- How do I tell if a token is expired?
- Read the exp claim: it is a Unix timestamp in seconds. If exp is earlier than the current time, the token has expired.
- Is my token sent anywhere?
- No. Decoding happens entirely in your browser, so the token never leaves your device — but still avoid pasting production secrets into any online tool.
Related tools
-
JSON Diff Checker Online
Compare two JSON objects online and highlight additions, removals, and changed values in structured data.
-
Microsoft Safelink Decoder Online
Decode Microsoft Outlook Safe Links to reveal the original protected URL for inspection and troubleshooting.
-
URL Encoder and Decoder Online
Encode and decode URL percent-encoded strings online for query parameters, links, APIs, and web debugging.
-
Base64 String Encoder and Decoder Online
Encode text to Base64 and decode Base64 strings online for API payloads, tokens, and data conversion.