tooldura
All tools

JWT Decoder

Decode a JWT, read every claim in plain English and check the signature

A leading Bearer, surrounding quotes and any line breaks are stripped for you, so paste the header line straight out of your terminal.

HS256354 characters
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjIwMjYtMDYta2V5In0.eyJpc3MiOiJodHRwczovL2F1dGguZXhhbXBsZS5jb20iLCJzdWIiOiJ1c2VyXzhmMTRlNDVmIiwiYXVkIjoiYXBpLmV4YW1wbGUuY29tIiwibmFtZSI6IkpvaG4gRG9lIiwiYWRtaW4iOnRydWUsImlhdCI6MTc3MDAwMDAwMCwibmJmIjoxNzcwMDAwMDAwLCJleHAiOjIxMDAwMDAwMDAsImp0aSI6IjljMWEwYzdlLTRiMmQifQ.PyrwkW70IxcayZeNLEeL95TA0ZFTcrS_fVxFzIp8ZZU
headerpayloadsignature

The shared secret the issuer signs with. It stays in your browser; nothing is sent anywhere.

header
{
  "alg": "HS256",
  "typ": "JWT",
  "kid": "2026-06-key"
}
payload
{
  "iss": "https://auth.example.com",
  "sub": "user_8f14e45f",
  "aud": "api.example.com",
  "name": "John Doe",
  "admin": true,
  "iat": 1770000000,
  "nbf": 1770000000,
  "exp": 2100000000,
  "jti": "9c1a0c7e-4b2d"
}
What the header says
algHS256 — Algorithm the signature was made with.
typJWT — Media type of the token itself, almost always JWT.
kid2026-06-key — Key id. Tells the receiver which key out of the issuer's set to verify with.
Claims in the payload
iss
https://auth.example.com

Issuer. Who minted and signed the token.

sub
user_8f14e45f

Subject. Who or what the token is about, usually a user id.

aud
api.example.com

Audience. Who the token is for; a receiver missing from this list should refuse it.

name
John Doe

Full name of the user, from OpenID Connect.

admin
true

Set by whoever issues the token; not part of any spec.

iat
1770000000

Issued at. When the token was minted.

nbf
1770000000

Not before. The token must be refused until this moment.

exp
2100000000

Expires at. The token must be refused at or after this moment.

jti
9c1a0c7e-4b2d

JWT id. Unique per token, so a replayed one can be spotted.

Times are shown in UTC, because that is what a NumericDate means. Anything the specs do not define is marked as the issuer's own.

About JWT Decoder

The JWT Decoder splits a token into its three sections, decodes the header and payload out of base64url, and lays the claims out with what each one means and when its timestamps actually fall. Registered claims from RFC 7519 and the usual OpenID Connect ones are named for you, so a payload full of azp, amr and auth_time reads as sentences rather than abbreviations. Give it the signing secret or the issuer's public key and it checks the signature too, through the browser's own crypto.subtle, which is the part a plain Base64 decoder can never do.

✦FreeNo paywalls or tiers
⬡No SignupNothing to create
⚡InstantNo setup, no install
⊞Any DeviceMobile, tablet, desktop

The guide behind this tool

Inside a JWT: Why Decoding a Token Proves Nothing

The claims are base64, not encryption, so the holder can read every one of them. What the signature settles, and the checks it quietly leaves to you.

9 min read

How to use JWT Decoder

  1. 1

    Paste the token. A leading Bearer, wrapping quotes and any line breaks the terminal added are stripped, so the whole Authorization header can go in as it is.

  2. 2

    Read the header and payload side by side, then use the claims table underneath for the meaning of each name and the UTC time behind each number.

  3. 3

    Paste the shared secret for an HS token, or the issuer's public key in PEM or JWK form for RS, PS and ES, to have the signature verified.

  4. 4

    Copy either decoded section with its own button.

Frequently Asked Questions

No. The decoding is string work and the signature check runs through crypto.subtle, both inside the page you are looking at. Nothing about the token or the key leaves the browser, which matters because a live access token is a credential: anyone holding it can act as you until it expires.