Skip to content

JWT Decoder

Read the contents of a JSON Web Token.

Decoding is not verification. A JWT payload is only Base64 — anyone can read it. Only a signature check proves it is genuine, and that needs the secret, which stays on your server.

This tool runs entirely in your browser. Nothing you enter is uploaded, stored or seen by us.

Decode a JWT and read its header, payload and expiry. This runs entirely in your browser, which for a token is not a nicety — pasting a live access token into a server-side tool hands it to whoever runs that server.