A JWT decoder is a free online tool that splits a JSON Web Token into its three parts and shows the header and payload as readable, pretty-printed JSON. Important honesty note: this tool decodes only. It does not verify the signature, so a decoded token is not proof the token is valid or trustworthy.
How do I decode a JWT online?
Paste the token into the box and press Decode. The header and payload appear as pretty-printed JSON, the algorithm is identified, and any exp or iat timestamps are converted to readable dates. The signature part is shown but never verified.
A JWT has three base64url-encoded parts separated by dots: header, payload, and signature. Decoding is just base64 decoding plus JSON parsing, which is why anyone holding the token can read it. That is also why tokens must travel over HTTPS and why sensitive data does not belong in a payload.
Does decoding a JWT verify its signature?
No. Decoding only reads the token; verification requires the secret key (for HMAC) or the public key (for RSA/ECDSA) plus a crypto check this tool deliberately does not perform. A successfully decoded token proves nothing about authenticity.
Treat any online decoder as a reading aid for tokens you already trust or for debugging your own development tokens. In production, always verify signatures on your own server with a proper JWT library, and never paste real user tokens or secrets into a browser tool.
Frequently asked questions
Is this JWT decoder free?
Yes. Decode unlimited tokens with no account and no limits. It runs entirely in your browser.
Can this tool verify a JWT signature?
No. It decodes only. Signature verification needs the secret or public key and a cryptographic check, which must happen on your own server with a proper library.
Why should I not paste real tokens here?
Anyone who can read a JWT can see its payload, and pasting a live token into any website exposes it beyond your control. Use throwaway development tokens for debugging.
What do the exp and iat fields mean?
exp is the expiration time and iat is the issued-at time, both as unix timestamps. The tool converts them to human-readable dates so you can see at a glance whether a token is expired.
What if my token has only two parts?
Then it is not a complete JWT. A JSON Web Token needs header, payload, and signature separated by two dots. Check for truncation when copying.