JWT Parser and Decoder Online

A JSON Web Token (JWT) is three URL-safe Base64 segments joined by dots: a header, a payload of claims, and a signature. This tool splits the token and decodes the header and payload so you can read exactly what an access or ID token carries — who issued it, who it is for, and when it expires. It is a decoder, not a validator: it does not check the signature, so a token that decodes cleanly here may still be forged or tampered with.

Because the payload is only encoded, never put secrets in a JWT — anyone holding the token can read every claim. Common claims include iss (issuer), sub (subject/user), aud (audience), exp (expiry, a Unix timestamp in seconds), iat (issued-at), and nbf (not-before).

How to use it

  1. Paste the full token (header.payload.signature) into the input.
  2. Read the decoded header to see the signing algorithm (the alg field) and token type.
  3. Read the decoded payload to inspect the claims — check exp against the current time to see whether the token is still valid.
  4. To confirm a token is authentic, verify its signature with the issuer's key in your backend; this tool does not do that.

Common use cases

Examples

Decode a JWT payload

Input eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjM0IiwibmFtZSI6IkppbSJ9.abc123

Output header: { "alg": "HS256" } payload: { "sub": "1234", "name": "Jim" }

The first two dot-separated segments are URL-safe Base64; decoding them reveals the header and claims. The signature (abc123) is left unchecked.

Frequently asked questions

What is a JWT?
A compact, URL-safe token of three Base64 parts — header, payload, and signature — used to carry authentication and authorization claims between services.
Does this tool verify the signature?
No. It only decodes the header and payload for inspection. Verifying authenticity requires the issuer's secret or public key, which you check server-side.
How do I tell if a token is expired?
Read the exp claim: it is a Unix timestamp in seconds. If exp is earlier than the current time, the token has expired.
Is my token sent anywhere?
No. Decoding happens entirely in your browser, so the token never leaves your device — but still avoid pasting production secrets into any online tool.

Related tools