JWT Decoder
About this tool
A JSON Web Token (JWT) is a compact, signed token with three Base64URL-encoded parts separated by dots: header, payload, and signature. Servers issue them after login and clients attach them to API requests as proof of identity, which is why you constantly encounter them while debugging authentication. The header names the signing algorithm (such as HS256 or RS256); the payload carries claims like the user ID (sub), the issue time (iat), and the expiry (exp). This decoder splits the token, pretty-prints both JSON parts, and translates the timestamps into readable dates with a clear expired-or-valid verdict. One critical point: decoding is not verification. Anyone can decode a JWT — the signature only proves it has not been tampered with, and checking that requires the secret key. Because decoding happens entirely in your browser, it is safe to inspect tokens here, but never paste production secrets into any online tool.
Privacy: all processing happens in your browser. Nothing is uploaded or stored.