SmartConvert

New: AVIF Converter is live — convert AVIF to JPG, PNG or WebP in bulk, right in your browser. Try it now

JWT Decoder

Decode JWT headers and payloads locally — no token ever leaves your device.

Runs locally in your browser — no upload.

Free Online JWT Decoder

JSON Web Tokens authenticate a huge share of today's APIs — and debugging them means answering quick questions fast: which algorithm signed this token? When does it expire? What claims does it actually carry? This decoder unwraps the Base64URL segments and pretty-prints the header and payload the moment you paste a token, so those questions stop requiring console gymnastics.

Paste any header.payload.signature string and you get all three parts laid out: the signing algorithm, every payload claim in readable JSON with one-click copy, and the signature segment itself. NumericDate claims like iat (issued at) and exp (expires at) are translated into unambiguous UTC timestamps — convert any epoch value further with the Timestamp Converter — alongside a live Expired / Not expired status based on your device clock, invaluable when diagnosing "token expired" errors or validating refresh windows.

Privacy is structural here: decoding is plain JavaScript executed entirely on your device. The token is never transmitted, logged or stored, and because signature verification would require your secret keys, this tool deliberately never asks for them. It is an inspection window, not a validator — exactly what you want when examining tokens from staging environments, CI logs or third-party integrations.

How to Use This Tool

  1. Paste the token — drop the complete three-segment string into the input box.
  2. Read the results — header and payload render as formatted JSON; expiry status updates automatically.
  3. Copy what you need — each panel has its own copy button for claims, header or signature.

Benefits

  • Instant full decode — header, payload and signature parsed as you type.
  • Human-readable dates — exp/iat shown as UTC timestamps with live expiry status.
  • Local by design — nothing leaves your browser; no secret keys ever requested.
  • Clear errors — malformed segments produce specific, actionable messages.
  • Free forever — unlimited decodes without signup.

Frequently Asked Questions

A JSON Web Token is a compact, signed credential made of three Base64URL segments separated by dots: a header describing the signing algorithm, a payload carrying claims (like user ID and expiry), and a cryptographic signature. JWTs are widely used for API authentication and single sign-on.

No — and that is by design. Signature verification requires the secret or public key, which should never be pasted into any website. This decoder only reads the header and payload so you can inspect claims; treat anything you see here as unverified information.

Decoding happens entirely in your browser with JavaScript — the token is never transmitted, logged or stored. Still, follow good hygiene: use test tokens when possible and never paste live production credentials into tools you do not control.

They are NumericDate claims measured in seconds since the Unix epoch. iat (issued at) records when the token was created; exp (expires at) records when it stops being valid. The converter shows both as UTC timestamps plus a live Expired/Not expired status computed from your device clock.

Common causes: copying only part of the token, extra spaces or line breaks inside it, a redacted signature segment left empty, or corrupted Base64URL data. Make sure you paste the complete header.payload.signature string exactly as issued.