Shard Tools

JWT Decoder

Decode a JSON Web Token and inspect claims and expiry in your browser.

Maintained by Roshan.

Browser-local decoder

Use JWT Decoder

Decoding is not signature verification. Treat a bearer token like a password.

Explore developer and data tools

Find related browser-local tools for nearby tasks without starting another search.

Browse all developer and data tools

About JWT Decoder

A JSON Web Token is three base64url segments joined by dots: a header describing the signing algorithm, a payload of claims, and a signature. Decoding reveals the first two instantly. The important thing to understand - and the thing most decoders bury - is that decoding is not verification. A token whose contents look correct can still be forged. This decoder makes that distinction explicit, and because a bearer token is a live credential, it does the work in your browser rather than sending it to anyone.

Using JWT Decoder

  1. The token is split on dots into its header, payload, and signature segments.
  2. The first two segments are base64url-decoded. Base64url replaces the '+' and '/' of standard base64 with '-' and '_' and drops the trailing '=' padding, so padding is restored before decoding.
  3. The decoded bytes are parsed as UTF-8 JSON and pretty-printed.
  4. Time-based claims are translated into readable dates: exp (expiry), iat (issued at), and nbf (not before) are all Unix timestamps in seconds, not milliseconds.
  5. The signature segment is displayed but not checked. Verifying it would require the signing key, which you should never paste into a web page.

Where jwt decoder helps

Debugging a 401 that looks correct

A token that decodes cleanly but returns 401 usually fails on aud or iss rather than expiry. Compare the aud claim against the API's expected audience before assuming a clock problem.

Clock skew on a freshly issued token

If nbf is a few seconds in the future relative to the verifying server, the token is rejected as not yet valid. Most libraries allow a small leeway setting for exactly this.

Before you use the result

Questions about JWT Decoder

Is it safe to paste a production token here?

This page decodes in your browser without sending the token in a request; verify that in the Network panel. Treat every bearer token as a live password, and rotate one if it was exposed to an untrusted service.

Why can't the tool tell me whether the token is valid?

Validity requires the signing key. For HS256 that is a shared secret and for RS256 it is the issuer's public key, fetched from a JWKS endpoint. Verifying in the browser would mean asking you to paste a secret into a web page, which is worse practice than the problem it solves.

What does 'alg: none' mean?

It declares an unsigned token. It exists in the specification for cases where integrity is guaranteed by another layer, but it is overwhelmingly seen as an attack: strip the signature, set alg to none, and hope the server trusts the header. Any verifier that accepts it is broken.

My payload shows a date in 1970. What went wrong?

The timestamp was read as milliseconds when JWT uses seconds. Multiply by 1000 before constructing a Date. This decoder handles the conversion for you in the formatted claim display.

Related tools

JSON Formatter and Validator

Format, minify, and validate JSON locally in your browser. Inspect keys, values, nesting depth, and root type without sending private API data to a server.

JSON to CSV Converter

Convert JSON objects to UTF-8 CSV in your browser. Union columns, quote values, and protect formula-like strings.

URL Encoder and Decoder

Percent-encode and decode URLs in your browser, choosing between encoding a value inside a URL and encoding a whole address. Shows which characters differ.

QR Code Reader

Decode a QR code from a photo or screenshot and read its destination as text before following it. Runs in your browser.

JSON to JSONL

Turn a JSON array into JSON Lines in your browser, one record per line, ready for streaming tools.