JWT Decoder

Decode a JSON Web Token's header and payload in your browser — see claims, expiry and issuer. No data sent anywhere.

Decoding only — this does not verify the signature. Everything runs in your browser; never paste production tokens you don't control.

How to use the JWT Decoder

  1. Paste the token. Drop in the full header.payload.signature JWT.
  2. Decode. View the header and payload as formatted JSON.
  3. Read the claims. See expiry, issued-at, issuer and subject if present.

Free to use — premium coming soon

FREE
  • Header & payload decode
  • Expiry/claim summary
  • 100% private
PREMIUM
  • Remove ads
  • Signature verification

About the JWT Decoder

A JWT Decoder splits a JSON Web Token into its three dot-separated parts and turns the first two back into readable JSON so you can inspect what a token actually carries. A JWT looks like xxxxx.yyyyy.zzzzz: the header, the payload, and the signature. The header and payload are Base64URL-encoded JSON, not encrypted, which means anyone holding the token can read them. This tool reverses that encoding and shows the header (the signing algorithm and token type) alongside the payload (the claims about the user or session), giving developers a fast way to see what is inside a token without writing throwaway code.

Reach for a decoder when you are debugging authentication: a login is rejected, an API returns 401, or a session expires sooner than expected. By decoding the token you can confirm which algorithm signed it (the alg field), check who issued it (iss), who it is about (sub), and exactly when it expires (exp). The exp and iat claims are Unix timestamps measured in seconds since 1970, not human-readable dates, so a good decoder converts them for you. Seeing those values side by side usually pinpoints the problem far faster than guessing at server logs.

Decoding works purely by reformatting, not by verifying. The tool takes each segment, replaces the URL-safe Base64 characters, decodes the bytes, and parses the resulting JSON. Crucially, it does not check the signature, because verifying authenticity requires the issuer's secret key (for HMAC algorithms like HS256) or public key (for RSA/ECDSA). That key should never be pasted into any web page. So a decoder tells you what a token claims, but never whether those claims are trustworthy or whether the token has been tampered with. Signature verification belongs on your server or in a local command-line tool.

Privacy note specific to this tool: a real token can contain user IDs, email addresses, organization identifiers, and permission scopes. Because the payload is only encoded, treat any token you decode as if its contents were written in plain text. Avoid pasting live production tokens into any online decoder you do not fully control, since third-party scripts, analytics, and browser extensions can read input fields on a page. For genuinely sensitive tokens, decode them locally or strip them to a non-production example first. Use this tool for development, debugging, and learning, not for handling credentials you cannot afford to leak.

Frequently asked questions

Does this tool verify the JWT signature?

No. It only decodes the header and payload so you can read the claims. Verifying the signature requires the issuer's secret or public key, which should never be entered into a web tool. Validate signatures on your server or with a local library instead.

Why can anyone read my token's contents?

The header and payload are Base64URL-encoded JSON, not encrypted. Encoding only makes the data compact and URL-safe; it does not hide it. Anyone with the token string can decode it, which is why you should never put passwords or secrets inside a JWT payload.

What do the exp and iat claims mean?

exp is the expiration time and iat is the issued-at time, both stored as Unix timestamps in seconds since January 1, 1970 (UTC). A token is no longer valid once the current time passes exp. The decoder converts these numbers into readable dates for you.

What are the most common standard claims I'll see?

The registered claims defined in RFC 7519 include iss (issuer), sub (subject, usually the user), aud (audience), exp (expiry), nbf (not valid before), iat (issued at), and jti (a unique token ID). They are kept to three letters to keep tokens small.

Is it safe to paste a production token here?

It is safer to avoid it. Live tokens often contain user IDs, emails, and permission scopes, and any page can be affected by third-party scripts or browser extensions reading the input. For sensitive tokens, decode them locally or use a sample token instead.

From our blog

How to Read, Fix, and Shrink JSON: A Practical Formatter Guide

By the Super Simple Digital Tools Team · Updated June 2026

JSON is everywhere in modern development, but it almost never arrives in a form you can read. API responses, webhook payloads, and minified config files tend to be a single dense line, and the moment the structure gets nested more than a level or two, scanning it by eye becomes guesswork. A formatter solves the first half of the problem by re-indenting that line into a tidy tree where every key sits at the depth it belongs to. The second half, validation, tells you whether the text is even legal JSON before you waste time debugging the wrong thing.

Start by pasting your text and formatting it. If it beautifies cleanly, the JSON is well-formed and you can read off the structure: objects in curly braces, arrays in square brackets, and indentation showing what is nested inside what. If formatting fails, the tool stops at the first syntax error and tells you the line and column. That location is the fastest path to a fix, because JSON parsers fail at the exact character where the grammar breaks, not at the conceptual mistake somewhere above it.

Most validation failures come down to a short list of habits borrowed from JavaScript or Python. Trailing commas are the number one offender: a comma after the last array element or object property is fine in JavaScript but illegal in JSON. Single quotes are second; JSON requires double quotes for every string and every key, with no exceptions for simple alphanumeric names. Comments are third, since JSON has no comment syntax at all. Knowing these three rules resolves the large majority of the errors people hit when writing JSON by hand.

Once your JSON is valid, minification is the inverse operation. The tool walks the parsed structure and writes it back with no spaces, no newlines, and no indentation, producing the smallest faithful representation of the same data. This is what you want when embedding JSON in a query string, a single-line environment variable, or a request body where every byte counts. Because both directions work from the same parsed tree, you can beautify to inspect, edit, and then minify again without any risk of the formatting step altering your values.

One thing a formatter does not do is judge whether your JSON is correct for its purpose. Syntactic validity only means the text follows the grammar; it says nothing about whether a field is named the way your API expects, whether a date string is in the right format, or whether a number is within an allowed range. Those are semantic concerns, and they belong to JSON Schema validation or to your application's own checks. Treat the formatter as the first gate that catches broken syntax cheaply, then layer schema validation on top when correctness of content matters.

  • If validation fails, look at the line just above the reported position first; a missing comma or an unclosed bracket often shows up as an error on the next token.
  • When pasting an API response from DevTools or curl, beautify it immediately so deeply nested fields become easy to trace before you start editing.
  • Use minify for values you have to fit on one line, such as a JSON-typed environment variable or a config field, but keep a beautified copy for editing.
  • If you need trailing commas or comments for readability, you are working in JSON5 or JSONC, not JSON; strip them before sending the data to a strict parser.

Read the full guide →

Tool by the Super Simple Digital Tools Team. Reviewed by our editorial team. Free to use, no signup required.

Related tools