DT Dev Tools

JWT Decoder

Decode JWT header and payload JSON locally in your browser. This tool does not verify signatures or validate trust.

🔒 Runs entirely in your browser — nothing is uploaded

Signature is decoded for display only and is not verified.

Advertisement

What JWT Decoder does

JWT Decoder splits a JSON Web Token into its three dot-separated segments, base64url-decodes the header and payload, and pretty-prints those JSON objects. It is useful when debugging login flows, API authorization headers, OAuth callbacks, refresh behavior, and tests that depend on claims such as subject, issuer, audience, issued-at time, and expiration time.

This page is designed for everyday developer work: quick checks while debugging, preparing small examples for documentation, and cleaning up data before pasting it into an editor, terminal, issue, or test fixture. The interface keeps the input, controls, output, and status message close together so the result is easy to verify before you copy it.

Private browser-based workflow

All processing happens with in-browser JavaScript. The tool does not upload your text, tokens, URLs, snippets, or generated values to a server, and it does not require an account. That privacy model is important because small utilities often receive real API responses, configuration samples, logs, authentication data, or customer-shaped examples during troubleshooting. Keeping the work local reduces risk and also makes the tool feel instant because there is no network round trip.

Practical tips

Decoding a token is not the same as trusting it. This browser page does not know your signing key, issuer rules, public key, or expected audience, so it cannot verify the signature. Use the output as a viewer only. Real applications must verify signatures and validate claims in trusted server-side or authentication code.

Always review transformed output before relying on it in production. Browser utilities are excellent for inspection and preparation, but they cannot understand every project convention or security requirement. If the result will be committed, shared publicly, or used in an authentication flow, double-check that it contains no secrets and that it matches the format expected by your application.

Reading the decoded output

Standard claims you will often see are iss (issuer), sub (subject), aud (audience), exp (expiration), nbf (not before) and iat (issued at). The time claims are Unix timestamps in seconds, and this tool shows them as raw numbers without converting them. For example, an exp of 1767225600 means 1 January 2026, 00:00 UTC. Multiply by 1000 before passing the value to a JavaScript Date.

The decoder expects exactly three dot-separated segments; anything else produces a decode error. Encrypted tokens (JWE) have five segments and cannot be read without the key, and a segment that is not valid base64url JSON will also fail. Remove any “Bearer ” prefix before pasting the token. The signature segment is displayed as-is, for reference only. Treat live tokens like passwords: although nothing leaves your browser here, avoid pasting production tokens into tools you do not trust or sharing decoded output publicly.

How to use

  1. Paste tokenAdd a JWT with three dot-separated segments.
  2. DecodeView the header, payload, and raw signature segment.
  3. Review safelyRemember that this tool does not verify the token.

Frequently asked questions

Does this verify signatures?
No. It only decodes header and payload JSON.
Can I decode production tokens?
It runs locally, but avoid sharing or saving sensitive tokens.
Why are exp values numeric?
JWT time claims are usually Unix timestamps.
Advertisement