JWT Decoder
SecurityDecode JWT tokens and inspect header, payload and claims
Your data is processed locally in your browser. Nothing is uploaded.
What is JWT Decoder?
A JSON Web Token (JWT) is a compact, self-contained token used widely for authentication and authorization. It consists of a header, a payload and a signature separated by dots. This decoder unpacks the header and payload and surfaces the registered claims — including the expiration time — entirely in your browser without verifying the signature.
How to use
- Paste the full JWT string into the input field.
- Click Decode to split the token into its three parts.
- Review the decoded header, payload and individual claims.
- Check the expiry status to see whether the token has already lapsed.
Use Cases
- Inspecting an access token returned by an API during integration work.
- Checking a token's expiry and scope claims before debugging a 401 error.
- Understanding the structure of tokens issued by OAuth or identity providers.