JWT Decoder
Decode JSON Web Tokens online and inspect JWT headers and payloads in a readable format. A quick and simple JWT debugging tool for developers.
JWT Decoder
Everything you enter is processed in your browser.
Signature unverified. Decoding a token does not establish that it is authentic or valid.
JWT Decoder
Decode JSON Web Tokens (JWTs) and inspect their contents in a clear, readable format.
Paste a JWT into the decoder to view its header and payload, making it easier to debug authentication, authorization and API integrations.
What is a JWT?
A JSON Web Token, commonly known as a JWT, is a compact format used to securely transmit information between systems.
JWTs are commonly used by web applications and APIs for authentication and authorization.
A JWT typically consists of three sections separated by periods:
header.payload.signature
For example:
eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjM0NTY3ODkwIn0.signature
What’s inside a JWT?
A typical JWT contains three components:
- Header – describes the token type and signing algorithm
- Payload – contains claims and information associated with the token
- Signature – allows the recipient to verify that the token has not been modified
The header and payload are Base64URL encoded, which means they can be decoded and inspected without access to the signing key.
Common JWT claims
JWT payloads can contain almost any information, but several standard claims are commonly encountered:
sub– Subject or identifier associated with the tokeniss– Token issueraud– Intended audienceexp– Expiration timeiat– Time the token was issuednbf– Time before which the token should not be acceptedjti– Unique identifier for the token
Applications can also include their own custom claims.
Why decode a JWT?
Decoding a JWT can be useful when working with:
- API authentication
- OAuth and OpenID Connect
- Identity providers
- Access and ID tokens
- Application authorization
- User claims
- Token expiration problems
- Authentication debugging
It provides a quick way to understand exactly what information has been included within a token.
Decoding is not verification
Decoding a JWT does not verify that the token is genuine.
The header and payload of most JWTs are encoded rather than encrypted, so their contents can be read without validating the signature.
Applications should always perform proper signature validation before trusting the claims contained within a JWT.
Be careful with sensitive tokens
JWTs can contain sensitive information and may provide access to applications or APIs.
Avoid sharing active access tokens with other people or pasting production credentials into tools you do not trust. Where possible, use expired, development or test tokens when debugging authentication problems.
Our Services
Build better tools, reduce repetitive work and make clearer technology decisions. Explore the service that fits your next challenge.

Custom Software Development
Build software that fits the way you work. Custom applications, business systems and integrations that reduce workarounds and support your next stage of growth.
$ Explore custom software development
Cloud Solutions
Move to the cloud or improve what you already run. Practical cloud architecture, migration and optimisation for reliable systems and more manageable costs.
$ Explore service
Process Automation
Spend less time on repetitive tasks. Connect your systems and automate data entry, documents and reporting so your team can focus on the work that needs them.
$ Explore service
Technology Consulting
Make technology decisions with a clearer plan. Practical advice on software, architecture and cloud options, grounded in your business needs and budget.
$ Explore service
Website Design & Hosting
Help visitors understand your business and take the next step. Website design, responsive development and reliable hosting, with support for ongoing changes.
$ Explore serviceOur Stats
A snapshot of the experience, technology and work behind what we do.
News
Get our latest articles, ideas and technology insights delivered directly to your inbox.
Read our Privacy Policy to learn how we handle personal information and how to contact us about your rights.
