ALL DEVELOPER TOOLS56
JWT Decoder
JWT Decoder — Inspect JSON Web Tokens Online
Paste a JWT to decode its header, payload, and check expiration.
About JWT Decoder
JSON Web Tokens (JWTs) are the industry standard for authentication and authorization across modern web applications and APIs. A JWT contains three Base64URL-encoded sections — the header (algorithm and token type), the payload (claims like user ID, roles, and expiration), and the signature. This tool splits a JWT into its three parts, decodes the header and payload, and displays each as formatted JSON you can copy with one click. It reads the exp (expiration) claim and tells you whether the token is still valid or has already expired, and shows the raw signature without verifying it — so never trust a token on the strength of what you read here. This is essential for developers debugging authentication flows, inspecting tokens returned by OAuth providers, verifying that tokens contain the expected claims, and troubleshooting authorization issues in API integrations. Simply paste your JWT and see the decoded contents instantly — no need to manually Base64-decode each section. The tool also shows the algorithm used for signing (HS256, RS256, etc.) so you can verify it matches your expectations.
Questions
Can this tool verify JWT signatures?
This tool decodes and displays the JWT header and payload, and checks expiration. It does not verify cryptographic signatures — that requires the signing secret or public key, which should never be pasted into a web tool.
Is my JWT token sent to a server?
No. The decoding happens entirely in your browser. Your token never leaves your device.
What are the three parts of a JWT?
A JWT is three Base64URL-encoded segments separated by dots: header (algorithm and token type), payload (your claims like sub, iat, exp), and signature (the HMAC or RSA signature over the first two segments).
How does the expiry check work?
The tool reads the exp claim — a Unix timestamp in seconds — converts it to an ISO date, and compares it against your device's clock to show a 'Token is valid' or 'Token is expired' banner with the exact expiry time. Tokens without an exp claim show 'none' in the rail and get no banner.
Why won't my token decode?
Usually because it isn't a signed JWT at all: the decoder needs exactly three dot-separated segments. Encrypted tokens (JWE) have five — their payload is actually encrypted, not just encoded, so it can't be inspected here — and opaque session tokens have no dots at all.
Is my file uploaded to a server?
No. Transmute processes everything locally in your browser using JavaScript and WebAssembly. Your files never leave your device — there is no server, no upload, no cloud processing.