JWT Decoder
Decode JWT headers and payloads locally in your browser and inspect common token time claims.
Paste a JWT
Decoding does not verify the token signature. Avoid pasting secrets into tools you do not trust; this decoder processes the token locally.
Token details
- Expires
- —
- Issued at
- —
What this JWT decoder does
A JWT normally contains three dot-separated parts: a header, a payload and a signature. This tool Base64URL-decodes the first two sections so you can inspect their JSON contents.
What it does not do
Decoding a JWT is not the same as verifying it. This page does not confirm that the signature is valid or that the token should be trusted.
Privacy
The token is decoded in your browser and is not sent to KRIYANO.
How to use this tool effectively
Decode the readable header and payload portions of a JSON Web Token without sending the token to a server. This helps developers inspect claims, expiration times and token structure while debugging authentication flows.
Common uses
- Inspect the alg and typ fields in a JWT header.
- Read application claims in the payload during authentication debugging.
- Convert exp, nbf or iat timestamp claims into understandable dates.
- Check whether a copied value has the three dot-separated parts expected of a JWT.
Example: inspect an expiration claim
Payload contains { "sub": "123", "exp": 1893456000 }sub: 123 exp: 1893456000
Decoding reveals the claim values. It does not prove that the token signature is valid or that the issuer should be trusted.
Common mistakes to avoid
- Decoding a JWT is not the same as verifying its cryptographic signature.
- Avoid pasting production tokens into third-party tools that transmit data to a server.
- Do not assume every JWT uses the same claims; applications can add their own fields.
The decoder runs locally in your browser. KRIYANO does not receive the token you paste into this page.
Frequently asked questions
Can this tool verify a JWT signature?
No. It decodes the header and payload for inspection. Signature verification requires the correct key and verification rules for the issuer.
Why can JWT payloads be decoded without a secret?
JWT header and payload segments are Base64URL encoded, not encrypted. The signature protects integrity; it does not hide the payload.
Should sensitive information be stored inside a JWT?
Treat ordinary signed JWT payloads as readable by anyone who obtains the token. Sensitive data should not be placed there unless an appropriate encrypted token format is used.