Online JWT Decoder Viewer
Paste a JWT token to instantly decode its Header and Payload as formatted JSON, with exp/iat/nbf timestamps converted to readable time. Supports Base64URL and unicode claims, decoded locally without signature verification.
How to Use
- Paste the full JWT token
- Header, Payload and expiry are parsed automatically
- Note: decodes content only; signature is not verified
- All encoding/decoding runs locally; sensitive content never leaves your device
Related Tools
FAQ
Does JWT decoding verify the signature?
No. This tool only performs Base64URL decoding and JSON formatting so you can inspect claims. It does not verify signatures and should not be used for authorization decisions.
Why does my token fail to decode?
Common causes: the token is not a standard three-part structure (header.payload.signature), a segment is not valid Base64URL, or the payload is not valid JSON. The tool reports the exact problem.
What are exp and iat fields?
They are standard JWT time claims in Unix seconds: iat is issued-at, exp is expiration, nbf is not-before. The tool converts them into readable UTC times automatically.