Free JWT Decoder — Decode & Inspect JSON Web Tokens
Welcome to the UtilixVerse JWT Decoder — a free, browser-based tool that decodes and inspects JSON Web Tokens without sending them anywhere. Paste a token (or use the Load Sample button) and instantly read its header, payload, andsignature information — algorithms, registered claims, expiration status, and more — all 100% privately in your browser.
How the JWT Decoder Works
A JWT is three base64url segments joined by dots — header.payload.signature. The decoder:
- 1. Splits the token into its segments and detects whether it is a signed token (JWS, 3 parts) or an encrypted token (JWE, 5 parts).
- 2. Decodes the header and payload from base64url to UTF-8 and parses them as JSON, with syntax highlighting.
- 3. Extracts registered claims —
iss,sub,aud,exp,nbf,iat,jti— converting timestamps to readable dates with expiry status. - 4. Reports the signing algorithm and signature size, and optionally verifies the signature for HS256/HS384/HS512 with a shared secret.
Understanding JWT Claims
Registered claims have standardized meanings: iss names the issuer, sub the subject, aud the intended audience, exp the expiration time (after which the token must be rejected), nbf the time before which it must not be accepted,iat the issue time, and jti a unique identifier. The decoder flags expired and not-yet-valid timestamps with color-coded status pills so you can tell at a glance whether a token is currently usable.
Signature Verification — Optional & Local
Decoding never needs the secret — the header and payload are plain base64url. If you also want to verify the signature, supply the shared secret for an HMAC token (HS256, HS384,HS512) and the tool recomputes the HMAC in your browser with the native Web Crypto API. The secret stays on your device. Asymmetric tokens (RS256, ES256, …) cannot be verified without the issuer's public key, and the tool says so rather than guessing.
Privacy & Security Notes
- ● 100% local — tokens are decoded in your browser; nothing is uploaded, logged, or stored.
- ● Careful with real tokens — a JWT payload can contain sensitive claims, so treat tokens from production systems like passwords even on local tools.
- ● Never put secrets in payloads — payloads are readable by anyone who has the token; only the signature protects integrity.
Pair this tool with our JSON formatter,hash generator, andbase64 encoderfor a complete developer toolkit.