Developer Tools
JWT Decoder
A token is often a working credential. This one decodes it in your browser, which is the only sane place to do it.
- Runs in your browser
- Nothing uploaded
The tool
Paste a token below. It is decoded in this browser and never sent anywhere.
Everything you enter stays on your own machine. Nothing is sent to us or to anyone else, which you can confirm in your browser network tab.
What people use it for
- Checking why an API call is returning 401
- Confirming what claims a token actually carries
- Reading a token expiry without a command line
- Debugging a login that works locally and fails in staging
- Inspecting a token you would rather not paste into a stranger server
About this tool
Why this matters more than most tools
A JWT from a live system is usually a working credential. Anyone holding it can act as that user until it expires. Pasting one into an online decoder hands a stranger a session, and most of those sites do the decoding on their server rather than in your browser. This one does the work locally, which you can confirm in the network tab.
Decoding is not verification
This reads what a token claims. It does not check the signature, because checking it needs the secret or public key the issuer holds. A token can be edited freely and will still decode perfectly, which is precisely why a server must verify rather than merely decode. If you are building the receiving end, verify the signature before trusting a single claim.
What the three parts are
A token is header, payload and signature, separated by dots and encoded as base64url. The header names the algorithm. The payload carries the claims: who the token is for, who issued it, when it was issued and when it expires. The signature is what makes the first two trustworthy, and only to somebody holding the key.
Reading the times
The exp, iat and nbf claims are Unix timestamps in seconds. This converts them and says whether the token has expired. An expired token that is still being accepted is a finding worth chasing, and so is a token with no expiry at all.
Need this handled across a whole website? See our Backend Web Development and Custom Web Apps page.
More tools and services
- JSON Formatter and Validator
- Base64 Decoder and Encoder
- URL Encoder and Decoder
- Colour Converter and Contrast Checker
- UUID Generator
- Unix Timestamp Converter
If you would rather someone did this properly for you, we offer Web Design Services and Website Development, SEO Services: Search Engine Optimization, AI Automation Agency.
Questions
Questions about this tool
The things clients actually want to know — costs, timelines, ownership and what happens after launch.
No. It is decoded by your browser and there is no request behind it. That matters because a token is often a live credential.
No, and nothing that decodes in a browser can. Verification needs the issuer key. Decoding tells you what a token claims, never whether the claims are genuine.
The exp claim is a Unix timestamp in seconds. If it is in the past the token has lapsed and a correctly built server will reject it.
No. A JWE is encrypted rather than merely encoded and cannot be read without the key.
Safer here than in a server-side decoder, because it stays local. Even so, rotate anything you have pasted somewhere you did not verify.
Free strategy session
Let’s build something worth finding.
Tell us where you want the business to be in twelve months. We will come back with a costed plan, a realistic timeline, and the numbers we expect to move — no obligation, no jargon.
- 30-minute call, no pitch deck
- Fixed-price proposal in 48 hours
- You own everything we build
Talk to a developer
Not a sales team
- Response time
- Within 1 business hour
- Where we work
- UK, USA & the Gulf
- Contracts
- No lock-in, monthly rolling
- Working since
- 2023