idpixo

JWT Decoder

Paste a JSON Web Token to read its header and payload claims. Nothing is sent anywhere.

Decoding is not verification. This tool does not check the signature, so a decoded token can still be expired, tampered with or forged. Never treat a token as valid just because it decodes.

Header

Payload

Key claims

How to read a JWT

A JWT has three parts separated by dots: header, payload and signature. This tool decodes the first two, which are only base64url-encoded (not encrypted) — anyone holding the token can read them. Common claims are exp (expiry), iat (issued at), nbf (not before), iss (issuer) and sub (subject). If a claim looks like base64url-encoded JSON, paste it into the JSON formatter for a cleaner view, and treat short text with the text case converter.

Frequently asked questions

Does this tool verify the JWT signature?
No. It only decodes the header and payload. Decoding is not verification: the signature is never checked, so a decoded token may still be forged or tampered with.

Is my token uploaded anywhere?
No. The decoding runs entirely in your browser using built-in functions. Your token never leaves your device.

Why does my token fail to decode?
A JWT has three dot-separated parts. If you see fewer or more, the string is not a JWT. If a part is not valid base64url-encoded JSON, that part is reported as invalid.

What does alg: none mean?
A token with alg: none claims there is no signature. This is a security red flag, so the tool shows a prominent warning when it sees it.

How do I read the exp, iat and nbf times?
They are shown as local dates, with exp marked expired or valid for a relative time, and nbf marked not yet valid if it is in the future.

Can I paste an Authorization header?
Yes. A leading Bearer prefix is stripped automatically, so you can paste the whole Authorization header value.

Related: reformat any decoded JSON with the JSON formatter, and browse every browser-only tool on the all tools page.

All tools →  JSON formatter →