Tooldeveloper

JWT Decoder

Decode and inspect JWT tokens instantly. Free JWT decoder showing header, payload, signature, and expiry.

Works Offline100% Free

Processed 100% locally in your browserPrivate & Safe

JWT Decoder runs entirely on your device using Web API standards. No data is ever uploaded to UtilixVerse servers.

Your Input
➔
Browser
➔
Result
No Server UploadsNo Account RequiredWorks OfflineZero Data Logging

JWT Token

Paste a JSON Web Token above to decode its header and payload. Try Load Sample for a ready-made token.

Free JWT Decoder — Decode & Inspect JSON Web Tokens

Welcome to the UtilixVerse JWT Decoder — a free, browser-based tool that decodes and inspects JSON Web Tokens without sending them anywhere. Paste a token (or use the Load Sample button) and instantly read its header, payload, andsignature information — algorithms, registered claims, expiration status, and more — all 100% privately in your browser.

How the JWT Decoder Works

A JWT is three base64url segments joined by dots — header.payload.signature. The decoder:

  1. 1. Splits the token into its segments and detects whether it is a signed token (JWS, 3 parts) or an encrypted token (JWE, 5 parts).
  2. 2. Decodes the header and payload from base64url to UTF-8 and parses them as JSON, with syntax highlighting.
  3. 3. Extracts registered claims — iss, sub, aud, exp, nbf, iat, jti — converting timestamps to readable dates with expiry status.
  4. 4. Reports the signing algorithm and signature size, and optionally verifies the signature for HS256/HS384/HS512 with a shared secret.

Understanding JWT Claims

Registered claims have standardized meanings: iss names the issuer, sub the subject, aud the intended audience, exp the expiration time (after which the token must be rejected), nbf the time before which it must not be accepted,iat the issue time, and jti a unique identifier. The decoder flags expired and not-yet-valid timestamps with color-coded status pills so you can tell at a glance whether a token is currently usable.

Signature Verification — Optional & Local

Decoding never needs the secret — the header and payload are plain base64url. If you also want to verify the signature, supply the shared secret for an HMAC token (HS256, HS384,HS512) and the tool recomputes the HMAC in your browser with the native Web Crypto API. The secret stays on your device. Asymmetric tokens (RS256, ES256, …) cannot be verified without the issuer's public key, and the tool says so rather than guessing.

Privacy & Security Notes

  • ● 100% local — tokens are decoded in your browser; nothing is uploaded, logged, or stored.
  • ● Careful with real tokens — a JWT payload can contain sensitive claims, so treat tokens from production systems like passwords even on local tools.
  • ● Never put secrets in payloads — payloads are readable by anyone who has the token; only the signature protects integrity.

Pair this tool with our JSON formatter,hash generator, andbase64 encoderfor a complete developer toolkit.

Frequently Asked Questions About the JWT Decoder

What is a JWT and what does this decoder show?

A JSON Web Token (JWT) is a compact, URL-safe token used to transmit claims between parties — most commonly for authentication and authorization. It has three base64url-encoded segments separated by dots: the header (algorithm and token type), the payload (the claims), and the signature. This decoder splits the token into those three segments, decodes the header and payload into readable JSON, highlights the syntax, lists the registered claims with human-readable timestamps, and reports the algorithm and signature size.

Is it safe to paste a token here? Do tokens get uploaded?

No — everything runs 100% locally in your browser. The token is decoded with plain JavaScript in your tab; nothing is ever sent to a server. That makes it safe to inspect tokens from production systems, provided you treat them with the same care you would give a password — a JWT payload can contain sensitive claims, so still avoid pasting tokens from critical accounts into any third-party page.

Can the token be decoded without knowing the secret?

Yes. The header and payload of a JWS token are not encrypted — they are only base64url-encoded, which is reversible without any key. Anyone can read them, which is why you should never put sensitive data in a JWT payload. The signature is the part that requires the secret to verify; the decoder still shows its byte length so you can confirm it is present.

How do the expiration claims work?

The exp (expiration time), nbf (not before), and iat (issued at) claims are Unix timestamps. The decoder converts them to your local date and time and shows a relative label such as "expires in 2 hours" or "expired 5 days ago". A token with an exp in the past must be rejected by the server; a token with an nbf in the future is not yet valid. The status pill next to each timestamp claim summarizes this at a glance.

Can this tool verify the signature?

Yes, for symmetric HMAC tokens (HS256, HS384, HS512) when you supply the shared secret. Verification runs entirely in your browser using the native Web Crypto API — the secret never leaves your device. Asymmetric tokens (RS256, ES256, etc.) cannot be verified without the issuer's public key, so the tool reports that clearly instead of guessing. Decoding the header and payload never requires the secret at all.

What is the difference between JWS and JWE?

JWS (JSON Web Signature) is the common form: header.payload.signature where the payload is readable but signed, so tampering is detectable. JWE (JSON Web Encryption) has five segments and the payload is actually encrypted, so it cannot be read without the decryption key. The decoder detects a five-segment token automatically and shows the JWE header while explaining that the payload requires a key.

Why do I see a decode error for some tokens?

The most common causes are: (1) the token is not actually a JWT (for example, an opaque session ID or a different format), (2) it has the wrong number of dot-separated segments, (3) a segment contains characters outside the base64url alphabet or is missing padding, or (4) the header or payload decodes to something that is not a JSON object. The decoder reports exactly which segment failed so you can diagnose the token.

Is this JWT decoder really free?

Yes — completely free, with no registration, no sign-up, no premium tier, and no data collection. Decoding, claim analysis, and HMAC verification all run locally on your device. Pair it with our JSON formatter, hash generator, and password tools for a complete developer toolkit.

Keep UtilixVerse Free

One-time contribution for hosting & new tools

Donate

Missing a Tool? Request It

Suggest new utilities or report bugs

Request Tool