JWT Decoder & Inspector
Decodes as you type. Tokens stay in your browser and are not saved.
Inspect a JSON Web Token locally. Paste or type a token and it decodes automatically — including a leading JWT, Bearer, or Token label. This does not verify signatures or decrypt JWE tokens.
Max 262,144 characters · auto-decodes on-device
Paste a JWT above — the decoded payload appears here. Decoding does not prove the token is authentic.
Online JWT Decoder, Parser & Inspector
Looking for a JWT decoder, JWT parser, or JWT token inspector? Toolshelf decodes JSON Web Tokens in your browser so you can read the header, payload, signature segment, algorithm, and registered claims — no signup and no uploads.
Paste a token, click Decode, and inspect issuer, subject, audience, issued-at, expiration, and not-before times as Unix timestamps plus local and UTC date/times. Decoding a JWT is not the same as verifying it.
What you can do with this JWT tool
- Decode JWT header and payload in your browser
- Inspect algorithm, token type, and compact structure
- Read issuer, subject, audience, and JWT ID claims
- Show iat, exp, and nbf as Unix, local, and UTC time
- Report expiration, issued-at, and not-before status
- Separate “can be decoded” from “signature is verified”
- Copy header, payload, or a full decoded summary
- Private by design: tokens are not uploaded or stored
What is a JWT?
A JSON Web Token (JWT) is a compact way to carry signed JSON claims between parties, defined in RFC 7519. The common compact form is three Base64URL segments separated by dots:
header.payload.signature
The header usually names the algorithm (alg) and type (typ). The payload is a JSON object of claims. The third segment is a digital signature or MAC — or empty for unsecured tokens. To encode or decode a single Base64 or Base64URL string (not a full JWT), use the Base64 Encoder & Decoder.
Decoding vs verification
Anyone who can see a JWT can decode the header and payload. Those parts are encoded, not encrypted. A decoder answers “what does this token say?” A verifier answers “did the expected issuer sign this exact header and payload?”
Token can be decoded
The compact string has valid Base64URL segments and the header (and JWS payload) parse as JSON objects. You can read claims such as sub and exp.
Token signature is verified
A cryptographic check with the correct key succeeded. This page never performs that check and will not label a token as verified.
Registered JWT claims
- iss — issuer, who created the token
- sub — subject, typically the user or client id
- aud — audience, a string or list of intended recipients
- exp — expiration time (Unix NumericDate)
- nbf — not-before time; the token should be rejected until then
- iat — issued-at time
- jti — JWT ID, a unique token identifier
How this JWT parser works
The decoder normalizes accidental whitespace and an optional Bearer prefix, splits on dots, and Base64URL-decodes each JOSE JSON segment as UTF-8. Invalid Base64URL, invalid JSON, missing segments, and non-object JSON produce an error. Time claims are interpreted as Unix seconds unless the number is large enough to be milliseconds.
Example compact JWT
The well-known jwt.io example decodes to algorithm HS256 and a payload with sub, name, and iat. You can paste it above to see the inspector output. The signature string is still not verified here.
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
Limitations
- Signatures and MACs are displayed, not verified.
- Encrypted JWE payloads cannot be read without a key.
- Payload fields are untrusted data and are never executed as code.
- Clock status uses your device time; server skew can differ.
Common ways people use this inspector
Debug API authentication
Paste an access token from a failing request and confirm which claims the issuer actually encoded — without sending the token to a third-party decoder.
Check expiry before retrying
See whether exp has already passed, how long until it expires, or whether nbf still blocks use.
Inspect issuer and audience
Confirm iss, aud, and sub match the API you are calling before you chase signature or clock-skew bugs.
Review tokens from logs
Decode compact JWTs copied from support tickets or local logs. Prefer redacted samples when tokens are still live.
Learn JWT structure
See header, payload, and signature segments side by side and read why decoding is not the same as verification.
Privacy-conscious inspection
Inspect production-like tokens on your device when you do not want to paste them into a hosted JWT debugger.
How to decode a JWT on Toolshelf
- 1Paste a token, use Paste, or pick a sample.
- 2Click Decode to inspect header, payload, and claims.
- 3Copy the header, payload, or decoded values. The summary states that the signature is not verified.
Frequently asked questions
- What is a JWT decoder?
- A JWT decoder (also called a JWT parser or JWT inspector) splits a compact JSON Web Token into header, payload, and signature, then Base64URL-decodes the JSON parts so you can read claims. It does not prove the token is authentic.
- Does decoding a JWT verify the signature?
- No. Decoding only reads the Base64URL-encoded JSON. Signature verification needs the correct secret or public key and a cryptographic check. This tool never claims a token is verified just because it can be decoded.
- Do I need an account to use this JWT decoder?
- No. Toolshelf JWT Decoder & Inspector requires no account and no uploads.
- Does this JWT inspector send my token to a server?
- No. Toolshelf decodes tokens locally in your browser. The JWT is not uploaded, not written to localStorage, and not placed in the page URL.
- What is the difference between JWS and JWE?
- A compact JWS (typical JWT) has three segments: header, payload, and signature. A compact JWE has five segments and encrypts the payload. This tool can read a JWE header but cannot decrypt the payload.
- Why are JWT timestamps shown three ways?
- Registered time claims (iat, exp, nbf) are Unix NumericDate values. This inspector shows the Unix seconds plus readable local and UTC date/times so you can compare them with logs and server clocks.
- Can I verify a JWT signature here?
- No. Verification would require a key and a crypto implementation for that algorithm. This page is a decoder and inspector only, so it will not mark a signature as verified.
- Is it safe to paste a live access token?
- Treat JWTs as secrets. On this page the token stays in memory in your browser tab and is not stored. Still avoid sharing live tokens in screenshots, tickets, or chat. Prefer expired fixtures when you only need to learn the format.
- What if my token has two segments or invalid Base64URL?
- A compact JWT needs three segments (or five for JWE). Missing dots, standard Base64 (+/) instead of Base64URL (-_), or JSON that is not an object will produce a clear error instead of a fake result.
- Does alg none mean the token is valid?
- No. alg "none" or an empty signature means the token is unsecured. Anyone can change the payload. This tool will still decode it and warn that it is unsecured — it will not treat that as cryptographic validity.
Related guides
Short articles that explain the problem this tool solves.
- How to Decode a JWT — Decode a JSON Web Token into header and payload JSON, read exp and iat claims, and understand why decoding is not signature verification.
Related tools
Continue with related browser-based tools on Toolshelf.
- Base64 Encoder & Decoder — Online Base64 encoder and decoder.
- URL Encoder & Decoder — Online URL encoder and decoder.
- JSON Formatter & Minifier — JSON formatter online: beautify, minify, and validate JSON in your browser.
- Unix Timestamp Converter — Epoch converter: Unix timestamp to date (and back).
- JSON to CSV Converter — Online JSON to CSV converter.
- Hash Generator — Online hash generator.
- Chmod Calculator — Chmod calculator online.
- Code Formatter & Beautifier — Online code formatter and beautifier.
Ready to inspect a JWT?
Scroll up, paste a token, and decode it locally. Remember: readable is not the same as verified.
Back to decoderExamples
Header and payload
Paste a three-part JWT. The decoder shows header and payload JSON. It does not verify signatures.
Use cases
- For Developers — Format JSON, test regex, decode JWTs, and work with timestamps.
What would you like to do next?
Continue working with the next step in this workflow. Recently used tools in this set are listed first.
- Hash Generator — Online hash generator.
- Base64 Encoder & Decoder — Online Base64 encoder and decoder.
- URL Encoder & Decoder — Online URL encoder and decoder.
- JSON Formatter & Minifier — JSON formatter online: beautify, minify, and validate JSON in your browser.
Related guides
Short articles that explain the problem this tool solves.
- How to Decode a JWT — Decode a JSON Web Token into header and payload JSON, read exp and iat claims, and understand why decoding is not signature verification.
You may also need
Continue with related browser-based tools on Toolshelf.
- Base64 Encoder & Decoder — Online Base64 encoder and decoder.
- URL Encoder & Decoder — Online URL encoder and decoder.
- JSON Formatter & Minifier — JSON formatter online: beautify, minify, and validate JSON in your browser.
- Unix Timestamp Converter — Epoch converter: Unix timestamp to date (and back).
- JSON to CSV Converter — Online JSON to CSV converter.
- Hash Generator — Online hash generator.
- Chmod Calculator — Chmod calculator online.
- Code Formatter & Beautifier — Online code formatter and beautifier.
Next steps
Related workflows on Toolshelf. These are curated paths, not usage rankings.
- Developer workflow — Format JSON, convert it to CSV, then inspect tokens.