JWT Decoder

Decode and inspect JSON Web Tokens (JWT) with color-coded Header, Payload, and Signature views, standard claims telemetry, and expiration countdowns.

JSON Web Token InspectorValid Structure
Encoded Token
Token Structure:
Header (Algorithm & Token Type)
Payload (Claims, Subject, Expiration)
Signature (Integrity Verification)
HEADER: Algorithm & Token Type
{ "alg": "HS256", "typ": "JWT" }
PAYLOAD: Data Claims
{ "sub": "usr_908231", "name": "Alex Rivera", "email": "alex@example.com", "roles": [ "admin", "developer" ], "iss": "https://auth.example.com", "aud": "https://api.example.com", "iat": 1727452800, "exp": 1790548800, "jti": "7ea94e18-2d26-44aa-8ca5-3169f2d86956" }
SIGNATURE: Cryptographic Hash
HS256
SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
Standard RFC 7519 Claims & Expiration Telemetry
Expiration (exp)Expired
Sep 27, 2026, 10:40:00 PM
5d ago
Issued At (iat)
Sep 27, 2024, 4:00:00 PM
735d ago
Subject (sub)
usr_908231
Issuer (iss)
https://auth.example.com
Audience (aud)
https://api.example.com
Token ID (jti)
7ea94e18-2d26-44aa-8ca5-3169f2d86956
100% Client-Side Inspection

Tokens are parsed entirely in your browser. No authentication secrets, keys, or claims are ever transmitted or saved.

Security Notice

Decoding only views claims. Always verify token cryptographic signatures on your backend before trusting authorization data.

How to use JWT Decoder

  1. 1Paste your encoded JSON Web Token (format: eyJhbGciOi... . eyJzdWIi... . ...) into the encoded token pane, or click 'Load Sample'.
  2. 2Inspect the color-coded tripartite architecture: Rose for Header, Violet for Payload claims, and Cyan for the Cryptographic Signature.
  3. 3Review the parsed JSON objects with formatted indentation and one-click copy buttons.
  4. 4Examine the 'Claims & Expiration Telemetry' dashboard to see localized expiration dates, human-readable relative time (e.g. 'Expires in 45m'), and active/expired status badges.
  5. 5Use the decoded subject (sub), issuer (iss), audience (aud), and token ID (jti) to debug authorization policies.

Key Features & Highlights

  • •RFC 7519 Tripartite Visualizer: Distinct color-coding demarcating the JWT Header (algorithm & type), Payload (claims & identity), and Signature.
  • •Automated Timestamp Humanizer: Converts raw UNIX epoch timestamps (exp, iat, nbf) into localized calendar times with live active/expired badges.
  • •Standard Claims Inspector: Specialized detection for registered RFC 7519 claims including Issuer (iss), Subject (sub), Audience (aud), and JWT ID (jti).
  • •Multi-Algorithm Support: Identifies HMAC (HS256, HS384, HS512), RSA (RS256, RS384, RS512), and ECDSA (ES256, ES384, ES512) signature headers.
  • •Zero-Server Data Transmission: Executed exclusively in local browser memory. No bearer tokens, private keys, or user identities are ever sent across the wire.
  • •Single-Click JSON Copy: Export cleanly indented header or payload JSON payloads directly to your clipboard for postman or integration testing.

Understanding JWT Decoder

Decode, inspect, and analyze JSON Web Tokens (JWT) conforming strictly to RFC 7519 specifications. Our in-browser JWT inspector unpacks the tripartite architecture (Header, Payload, and Signature) with syntax highlighting, automatic timestamp translation (exp, iat, nbf), live expiration countdowns, and claims telemetry. Perfect for debugging OAuth 2.0, OpenID Connect (OIDC), Supabase, Firebase, and Auth0 tokens with zero risk of credential leakage — 100% client-side with zero server contact.

Frequently Asked Questions

What is a JSON Web Token (JWT)?

A JSON Web Token (RFC 7519) is a compact, URL-safe means of representing claims to be transferred between two parties. It consists of three Base64URL-encoded parts separated by periods: the Header (specifying cryptographic algorithm and token type), the Payload (containing user identity and session claims), and the Signature (verifying that the message has not been altered in transit).

What is the difference between decoding a JWT and verifying a JWT?

Decoding a JWT simply unpacks the Base64URL-encoded JSON payload so you can read the claims and expiration date. Anyone with the token can decode it without a secret key. Verifying a JWT, on the other hand, cryptographically validates the signature using a shared secret (for HMAC algorithms like HS256) or a public key (for asymmetric algorithms like RS256) to ensure the token was generated by a trusted authority and was not tampered with.

What do the standard JWT claims 'exp', 'iat', and 'nbf' mean?

'exp' (Expiration Time) is a UNIX timestamp after which the token must not be accepted. 'iat' (Issued At) indicates the exact second the token was created. 'nbf' (Not Before) specifies the timestamp before which the token must not be accepted by a resource server.

Is it safe to paste my production JWT into this tool?

Yes! Unlike many online JWT inspectors that send tokens to a backend server for parsing, our tool decodes the token 100% inside your local web browser using client-side JavaScript. Your tokens, user identities, and authorization scopes never leave your computer.

Can I edit the JWT payload and re-sign it?

While you can edit the JSON payload, creating a valid new signature requires the original private key or HMAC secret key known only to your authorization server. Without that secret, any signature generated would be rejected by your backend API.

Related Free Tools

Explore complementary utilities to boost your workflow

View all free tools →