JWT Decoder
Decode any JWT instantly — inspect the header, payload claims, and expiry with human-readable timestamps. 100% client-side; tokens never leave your browser.
How JWT works
A JSON Web Token, as defined in RFC 7519, has three Base64url-encoded sections separated by dots. The header specifies the signing algorithm (e.g., HS256, RS256). The payload contains claims — key-value pairs like user ID, roles, and expiry. The signature is created by signing the header and payload with a secret or private key, per the JSON Web Signature structure in RFC 7515.
Anyone can decode the header and payload without a key — they're just Base64url encoding, not encryption. Only the signature requires the key. This means sensitive data should never go in the payload unless the entire token is encrypted (JWE).
Common debugging uses
- Check if a token is expired (exp claim)
- Confirm which user or session a token belongs to (sub claim)
- Inspect role or permission claims your API is reading
- Debug authentication issues in development
- Validate token structure before implementation
JWT security tips
- Don't store sensitive data in the payload — it's not encrypted, just encoded.
- Set short expiry times — 15 minutes to 1 hour for access tokens, longer for refresh tokens.
- Use RS256 over HS256 in multi-service architectures — each service can verify without sharing the secret.
- Validate the signature server-side — never trust a token the client modifies.
JWT vs session tokens — when to use each
JWTs are stateless — the server does not need to look up a session in a database to validate the token. This makes them ideal for microservices and APIs where multiple services need to authenticate the same user without sharing a session store. The downside is that JWTs cannot be immediately revoked: once issued, they are valid until they expire. For logout-on-demand functionality, you need a token revocation list or very short expiry times combined with refresh tokens.
Traditional session cookies are stored server-side: easy to revoke, but require a shared session store (Redis, database) that all services can access. Choose JWTs for stateless APIs and microservices; choose sessions for monolithic applications where immediate logout is a requirement.
Frequently asked questions
- What is a JWT?
- JWT (JSON Web Token) is an open standard (RFC 7519) for securely transmitting information as a JSON object. It consists of three parts separated by dots: a Header (algorithm), a Payload (claims), and a Signature. JWTs are commonly used for authentication and API authorization.
- Is it safe to paste my JWT here?
- Yes. This tool runs entirely in your browser — no data is sent to any server. That said, treat JWTs like passwords: avoid pasting production tokens from sensitive systems into public tools as general best practice. Use test tokens for debugging.
- Can this verify the JWT signature?
- No. Signature verification requires the secret key (for HMAC) or the public key (for RSA/ECDSA). Since this is a client-side tool, the secret is never available here. Decoding the payload is always possible without the key — which is why sensitive data should never be stored unencrypted in a JWT payload.
- What are common JWT claims?
- Standard claims include: sub (subject/user ID), iss (issuer), aud (audience), exp (expiry timestamp), iat (issued at), nbf (not before). Custom claims are anything else your application adds, like roles, permissions, or user metadata.
- Can I decode a JWT without the secret key?
- Yes — the header and payload are just base64url-encoded JSON, readable by anyone who holds the token. The secret key is only needed to VERIFY the signature (i.e., prove the token wasn't tampered with), not to read its contents. That's also why you should never put sensitive data inside a JWT payload.
- Why does my JWT fail to decode?
- A valid JWT is three base64url sections separated by dots: header.payload.signature. The usual culprits are a truncated copy-paste (check the token ends after the third section), surrounding quotes or a 'Bearer ' prefix pasted along with it, or line breaks introduced by an email client. Strip those and paste the bare token.
From the blog
- CORS Errors Explained: Why Your Browser Blocks the Request (and the Exact Headers That Fix It)
A scenario-first walkthrough of how CORS works — why the Same-Origin Policy exists, what each CORS error message means, preflight requests explained, and exactly which server headers fix the problem.
- What is a JWT? How to decode and verify JSON Web Tokens
JWT tokens are everywhere in modern web auth — but what's actually inside them? Learn to decode, read, and verify JWTs instantly without installing anything.
- Developer Tools for Beginners: 12 Browser-Based Utilities You'll Use Every Day
You don't need to install anything to use these developer tools. They run in your browser, handle the tasks you'd otherwise Google, and work on any device.
Related tools
- Base64 Encoder / Decoder
Encode text to Base64 or decode Base64 back to plain text instantly in your browser — no upload, no sign-up, and nothing leaves your device.
- Hash Generator
Generate SHA-1, SHA-256, SHA-384, and SHA-512 hashes for any text instantly — free, client-side, nothing leaves your browser. Compare and copy in one click.
- jwt.io Alternative
A private jwt.io alternative: decode JWT header and payload 100% in your browser, with expiry warnings and integrated Base64, hash, and regex tools.
- JSON Formatter, Validator & Repair Tool
Format, minify, validate, and repair JSON in your browser. Sort keys, auto-format on paste, escape/unescape strings — free, no sign-up, 100% client-side.