Loading tool...
JWT Decoder — Free Online Tool
A JSON Web Token is a compact string made of three Base64URL parts separated by dots: a header describing the algorithm, a payload carrying claims such as the user id, issuer and expiry, and a signature. This JWT decoder splits the token you paste, decodes the first two parts and prints them as formatted JSON so you can inspect exactly what an authentication server issued. Time-based claims such as iat, nbf and exp are converted to readable local dates, and the tool tells you at a glance whether the token has already expired, which is the most common reason for a sudden 401 error. Developers use this when debugging login flows, checking OAuth and OpenID Connect responses, confirming which scopes or roles were granted and verifying that a backend is putting the right claims into a token. Decoding happens entirely in your browser, so the token never leaves your device, though you should still avoid pasting live production tokens into any website you do not trust. Important: decoding is not verification. Anyone can read a JWT payload, so never store secrets inside it, and always verify the signature on your server with the correct key before trusting any claim. This tool deliberately does not validate signatures. Use the sample button to see how a typical token is laid out.
Use our JWT Decoder on AllConvertor — no registration, no download, works on iPhone, Android, Windows, and Mac. All processing runs in your browser when possible for maximum privacy and speed.
How to use JWT Decoder
- Paste your JWT into the encoded token box.
- Check the decoded header and payload.
- Review the iat, nbf and exp dates and the expiry status.
- Copy the claims you need for debugging.
- Clear the field when you finish.
Key benefits
- ✓ 100% free — no paywall or trial limits
- ✓ No account or email required
- ✓ Mobile-friendly responsive design
- ✓ Instant results in your browser
- ✓ Secure — data stays on your device
- ✓ Trusted by thousands of users daily
Popular searches
Frequently Asked Questions
What is a JWT?
A JSON Web Token is a compact, URL-safe string used to carry claims between parties, commonly for authentication. It has a header, a payload and a signature, separated by dots.
Does this tool verify the JWT signature?
No. It only decodes the header and payload. Signature verification requires the secret or public key and must be done on your server before you trust the token.
Is it safe to paste my token here?
Decoding happens locally in your browser and nothing is sent to a server. Even so, avoid pasting active production tokens into any online tool and use test tokens when possible.
How can I tell if my JWT has expired?
Look at the exp claim. The tool converts it to your local date and shows a clear expired or not expired message based on the current time.
Why does my token fail to decode?
The most common causes are a truncated token, missing dots or extra whitespace and quotes. A valid JWT always has exactly three dot-separated parts.