Skip to main content

JWT Decoder

Decode and inspect JSON Web Tokens online. View JWT headers, payload claims, timestamps and expiration status directly in your browser.

JWT Decoder

JWT Decoder

Online tool

Browser-local Ctrl/Cmd + Enter decode Esc clear

Paste a compact JWT or a Bearer value.

JWT status
Decode, inspect and verify independently.
Segments
Claims
Expires
Remaining
Verification
⚡

Fast to use

Designed to help you complete the task without unnecessary steps.

◇

Works in your browser

No separate desktop software is needed for this online tool.

✓

Simple workflow

Enter your information, use the tool and work with the result.

What Is a JWT Decoder?

A JWT decoder is a tool that converts the readable parts of a JSON Web Token from Base64URL-encoded data into structured JSON. A typical JWT contains three dot-separated sections: a header, a payload and a signature.

The header usually contains token metadata such as the signing algorithm and token type. The payload contains claims such as the issuer, subject, audience, issued-at time and expiration time. A decoder lets you inspect these values without needing the signing secret or private key.

A JWT decoder should not be confused with a JWT signature verifier. Decoding reveals what the token contains; verification checks whether the token was signed correctly with the appropriate cryptographic key.

How to Decode a JWT Token Online

To decode a JWT token, paste the complete token into the JWT Decoder and select Decode JWT. A standard JWT normally contains three sections separated by periods:

header.payload.signature

The decoder reads the Base64URL-encoded header and payload and displays them as formatted JSON. You can then inspect the token information, algorithm, claims, timestamps and individual JWT sections.

If you have copied a token from an HTTP authorization header, remove the surrounding Bearer prefix if necessary. A decoder can read the JWT itself; the authentication scheme is separate from the token's encoded contents.

Understanding the JWT Header, Payload and Signature

A JSON Web Token is commonly represented as three Base64URL-encoded sections separated by periods.

  • Header: Contains metadata about the token, commonly including alg for the signing algorithm and typ for the token type.
  • Payload: Contains claims and application-specific data carried by the token.
  • Signature: Represents the cryptographic signature associated with the encoded header and payload.

The header and payload can normally be decoded without a secret because Base64URL encoding is not encryption. Reading those sections does not establish that the token is authentic.

JWT Claims Explained

JWT claims are pieces of information contained in the payload. Common registered claims include iss, sub, aud, exp, nbf, iat and jti.

  • iss identifies the issuer of the token.
  • sub identifies the subject represented by the token.
  • aud identifies the intended audience.
  • exp specifies when the token expires.
  • nbf specifies the time before which the token should not be accepted.
  • iat records when the token was issued.
  • jti can provide a unique identifier for the token.

Applications can also include custom claims for roles, permissions, tenant information and other application-specific data.

How to Check JWT Expiration

The exp claim is commonly used to specify the expiration time of a JWT. JWT time claims are normally represented as NumericDate values, which are based on Unix time in seconds.

This decoder interprets supported time claims and presents them in a human-readable date format. The expiration status helps you quickly determine whether a decoded token has passed its stated expiration time.

The nbf claim can also be useful when debugging authentication problems because it indicates a time before which the token should not be accepted.

JWT Decoding vs JWT Signature Verification

Decoding and verification are different operations.

Decoding reads the Base64URL-encoded header and payload and converts them into JSON. It does not require a signing secret or public key.

Signature verification uses the appropriate cryptographic algorithm and verification key to determine whether the signature matches the token's encoded header and payload.

A token that decodes successfully is not automatically trustworthy. Authentication and authorization decisions should rely on verification performed by the appropriate application or trusted authentication system.

Can You Decode a JWT Without a Secret?

Yes. You do not need the signing secret or private key to decode the header and payload of a normal JWT. Those sections are encoded using Base64URL rather than encrypted with a secret.

The signing key becomes relevant when verifying the token's signature. Therefore, being able to read a JWT does not mean that you can prove who issued it or that its claims are authentic.

Is a JWT Encrypted?

Not every JWT is encrypted. A commonly used signed JWT, also called a JWS, contains a Base64URL-encoded header and payload plus a signature. Base64URL encoding makes the data suitable for compact transmission but does not hide the contents.

If confidential information must be protected cryptographically, an application needs an appropriate encryption mechanism rather than assuming that a signed JWT automatically provides confidentiality.

JWT Decoder for API and Authentication Debugging

JWTs are frequently encountered while debugging authentication and API requests. A decoder can help developers inspect whether expected claims are present, identify the signing algorithm listed in the header, and check timestamps such as iat, nbf and exp.

This can be useful when investigating access-token behavior, OAuth or OpenID Connect integrations, API authorization problems, and authentication flows involving identity providers or web applications.

The decoder shows the contents of the token, but it does not replace the verification performed by the application receiving the token.

JWT Decoder and Browser-Based Processing

AabiTech performs the JWT decoding operation in your browser using client-side JavaScript. The token does not need to be submitted to AabiTech's server or an external decoding API for the decoding operation.

Even when a tool performs processing locally, JWTs can contain authentication credentials or sensitive claims. Avoid sharing tokens unnecessarily and use appropriate caution with live production credentials.

Questions & answers

Frequently Asked Questions

What is a JWT decoder?
A JWT decoder converts the Base64URL-encoded header and payload of a JSON Web Token into readable JSON so you can inspect the token structure and claims.
How do I decode a JWT token online?
Paste the complete JWT into the decoder and select Decode JWT. The tool separates the header, payload and signature, then displays the decoded header and payload as formatted JSON.
Can I decode a JWT without the secret?
Yes. Decoding the header and payload does not require the signing secret or private key because those sections are Base64URL-encoded rather than encrypted.
Does decoding a JWT verify its signature?
No. Decoding only reveals the encoded contents. Signature verification requires the appropriate cryptographic algorithm and verification key.
What are the three parts of a JWT?
A typical JWT contains a header, payload and signature separated by periods: header.payload.signature.
What does the JWT exp claim mean?
The exp claim specifies the expiration time of a JWT. It is normally represented as a NumericDate based on Unix time in seconds.
What do iat and nbf mean in a JWT?
iat commonly represents the time when the token was issued, while nbf specifies the time before which the token should not be accepted.
What do iss, sub and aud mean in a JWT?
iss identifies the issuer, sub identifies the subject, and aud identifies the intended audience of the token.
Is a JWT encrypted or just encoded?
A typical signed JWT uses Base64URL encoding for its header and payload. Encoding is not encryption, so those sections can normally be decoded without a secret.
Can I decode a Bearer token with a JWT decoder?
Yes. A Bearer token is an HTTP authentication scheme. Once the Bearer prefix is removed, the JWT itself can be decoded as a three-part token.
What algorithms can this JWT decoder read?
JWT decoding does not require cryptographic verification of the algorithm. The decoder reads the alg value from the header and can display it regardless of whether the token uses HS256, HS384, HS512, RS256, ES256 or another JWT algorithm identifier.
Does the AabiTech JWT Decoder upload my token?
The JWT decoding operation runs locally in your browser, so the token does not need to be uploaded to AabiTech or sent to an external decoding API.
Can a decoded JWT be trusted?
A successful decode does not prove that a JWT is authentic. The token must be verified using the appropriate signature algorithm and trusted verification key before its claims are relied upon for security decisions.
Can I use the JWT decoder to debug an API authentication problem?
Yes. Inspecting the header, claims and time values can help identify missing claims, unexpected algorithms, expired tokens and not-yet-valid tokens during API and authentication debugging.

Explore more AabiTech tools

Browse the complete collection of practical online tools for development, text, design, calculations and everyday digital work.