Search 93+ free tools… (e.g. json, vpn, password) ⌘K
Link Tools Dereferer Hide Referrer Link URL Shortener Affiliate Cloaker PayPal Links PayPal DonationPayPal Links Privacy Tools Password Generator Cloudflare Resolver My Referrer Torrent Tools Magnet → Torrent Torrent → Magnet Torrent Editor Pirate Bay Proxies Movierulz Proxies ExtraTorrent Proxies Dev Tools Base64 Encoder Hash Generator HTTP Headers Disposable Email Checker Company Blog About Us Contact Anonymize Free
Dev Tool

JWT Decoder

Decode any JSON Web Token instantly. View header, payload and signature. Check expiry and claims. Runs entirely in your browser.

Paste your JWT token
🔑
What is JWT?
JSON Web Tokens are a compact way to securely transmit information between parties. They are widely used for authentication and authorization.
🔍
What this decodes
The header (algorithm and token type), payload (claims like user ID, roles, expiry) and the signature block (cannot be verified without the secret).
🔒
100% private
Your JWT never leaves your browser. Decoding happens entirely client-side — never share real tokens with online tools that send them to servers.

Frequently Asked Questions

What is a JWT and what information does it contain?
A JSON Web Token (JWT) is a compact token consisting of three Base64-encoded parts: the header (algorithm and token type), the payload (claims such as user ID, roles, and expiry), and the signature. The payload contains the actual data your application uses for authentication and authorisation.
Does the JWT decoder verify the signature?
The decoder shows you the decoded header and payload without verifying the cryptographic signature, since signature verification requires the secret or public key. To verify a JWT's authenticity you need to validate it server-side using your application's secret key.
Is it safe to paste a production JWT into this tool?
Decoding happens entirely in your browser — the token is never sent to our servers. However, as a general security practice, avoid pasting real production tokens containing active user sessions into any online tool. Use test or expired tokens when debugging.
What is a JWT?
A JSON Web Token (JWT) is a compact, URL-safe token format used for authentication. It consists of three Base64url-encoded parts separated by dots: a header (algorithm info), a payload (claims/data), and a signature for verification.
Can you verify the JWT signature?
Signature verification requires the secret key or public key used to sign the token. Since this tool runs in your browser and has no server, it cannot verify signatures. It decodes and displays the header and payload claims only.
Is it safe to paste my JWT here?
This tool runs entirely in your browser — your JWT is never transmitted to any server. However, be cautious about pasting real production tokens into any online tool. Use test tokens where possible.
🛡️
Your IP address and DNS queries are visible to your ISP. Protect your privacy with a trusted VPN — tested and recommended by Anonymiz.
See Recommended VPNs →

What is inside a JWT

A JSON Web Token is three Base64URL-encoded parts separated by dots: a header, a payload and a signature. The header names the signing algorithm, the payload holds claims such as a user ID and an expiry time, and the signature proves the token was issued by someone holding the right key. Decoding shows the header and payload in readable form.

Decoding is not verifying

Anyone can decode a JWT, because the payload is only encoded, not encrypted. So never put secrets, or personal data you would not show the user, inside a token, and never trust a token's contents until the server has checked its signature with the correct key.

Claims worth checking

  • exp is the expiry time as a Unix timestamp. Expired tokens are a common cause of sudden 401 errors.
  • iat and nbf say when the token was issued and when it becomes valid. A clock difference between servers can make a fresh token look invalid.
  • iss and aud say who issued it and who it is for. An API should reject tokens meant for another audience.
  • sub identifies the user or thing the token is about.

Security mistakes

  • Trusting the header's algorithm. Accepting alg: none, or letting the token choose its own algorithm, has let attackers forge tokens. Servers should accept only the algorithm they expect.
  • Weak secrets. A short HS256 secret can be cracked offline from a single token. Use long random secrets, or asymmetric keys such as RS256 made with the RSA key generator.
  • Long-lived tokens are hard to revoke. Keep access tokens short-lived and refresh them.
  • Pasting live tokens. A valid token grants the same access as a password until it expires, so decode test tokens rather than ones from real sessions.

Related Tools

🔡
Base64 Encoder
JWTs are Base64-encoded
#️⃣
Hash Generator
MD5, SHA-1, SHA-256 hashes
📋
JSON Formatter
Format and validate JSON
🆔
UUID Generator
Generate v4 UUIDs in bulk
⏳
Timestamp Converter
Decode exp and iat claims
🔗
URL Encoder
Encode and decode URLs safely
Done!