Paste a JWT and read it: header, payload, algorithm, and the time claims turned into real
dates — with an unmissable EXPIRED / still-valid verdict on exp, and the honest banner every
decoder should carry: decoding is not verification.
How to decode a JWT
- Paste the token — decoding is instant and local.
- Read the verdict chips: algorithm, expiry (with EXPIRED status), issued-at, not-before.
- Inspect the pretty-printed header and payload; copy the payload JSON if you need it.
What a decoder is actually for
Nine times out of ten: why did this request get a 401? The answer is in the claims — the
token expired an hour ago, the aud doesn’t match, the sub is the wrong user, the clock skew
put nbf in the future. A decoder turns the opaque eyJ… blob into those answers in seconds.
The header tells you the algorithm your verifier must expect; a missing signature part or
"alg": "none" tells you something is very wrong.
The line this tool won’t blur
JWTs are readable by design — base64url is encoding, not encryption — which means anyone can decode one; the security lives entirely in the signature that this tool does not and cannot check. Never make an authorization decision from decoded claims, and never assume a token is genuine because it parses. (That base64url layer is the same one in the Base64 tool; raw timestamps convert in the timestamp converter, and the payload prints nicely in the JSON formatter.)
Private by design
Tokens are credentials. This decoder runs entirely on your device — the token never travels, which is the one property a JWT tool must have.