🔐JWT Decoder & Encoder
Free jwt decoder online — decode, verify, and encode JSON Web Tokens instantly, entirely in your browser.
Decoded header Decoded payload Signature (base64url) Your signed JWT will appear here… Sample Tokens — Click to Load
Try these real-world examples. Click "Load →" to paste any token into the decoder and inspect its claims instantly.
Secret: your-256-bit-secret (verifiable)
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
Realistic access token, exp in Aug 2023
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c2VyXzg4ZjNrMjEiLCJuYW1lIjoiQWxleCBDYXJ0ZXIiLCJlbWFpbCI6ImFsZXhAZXhhbXBsZS5jb20iLCJyb2xlcyI6WyJhZG1pbiIsImVkaXRvciJdLCJpc3MiOiJodHRwczovL2F1dGguZXhhbXBsZS5jb20iLCJhdWQiOiJodHRwczovL2FwaS5leGFtcGxlLmNvbSIsImlhdCI6MTY5MzQyMDgwMCwiZXhwIjoxNjkzNTA3MjAwfQ.dGhpcyBpcyBhIHNhbXBsZSBzaWduYXR1cmU
Machine token with custom permissions
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJzdmNfcGF5bWVudF9hcGkiLCJzZXJ2aWNlIjoicGF5bWVudC1zZXJ2aWNlIiwiZW52IjoicHJvZHVjdGlvbiIsInBlcm1pc3Npb25zIjpbInJlYWQ6dHJhbnNhY3Rpb25zIiwid3JpdGU6dHJhbnNmZXJzIl0sImlzcyI6Imh0dHBzOi8vYXV0aC5pbnRlcm5hbCIsImlhdCI6MTcxNjIzOTAyMn0.dGhpcyBpcyBhIHNhbXBsZSBzaWduYXR1cmU
Refresh token with 30-day expiry from 2024
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c2VyXzg4ZjNrMjEiLCJ0eXBlIjoicmVmcmVzaCIsImp0aSI6InJ0b2tfOWYzYTJjMWQ4ZTdiNmEwNSIsImlzcyI6Imh0dHBzOi8vYXV0aC5leGFtcGxlLmNvbSIsImlhdCI6MTcxNjIzOTAyMiwiZXhwIjoxNzE4ODMxMDIyfQ.dGhpcyBpcyBhIHNhbXBsZSBzaWduYXR1cmU
Free JWT Decoder Online — Inspect Any Token Instantly
Need to inspect a JWT without pasting it into a sketchy site? Our free JWT Decoder & Encoder instantly decodes any JSON Web Token the moment you paste it in. As a fast and reliable jwt decoder online, it splits your token into its header, payload, and signature and displays the claims in clean, readable JSON — so you can see exactly what's inside in seconds.
But it does more than decode. Check token expiry at a glance, verify the signature against a secret or key, and encode and sign your own tokens for testing. Whether you're debugging an auth flow, inspecting API credentials, or building login functionality, everything you need is right here.
Simply paste your token to decode it, or build one to encode. Everything runs in your browser — no sign-up, no downloads, no limits, and your tokens never leave your device.
What This JWT Tool Does
- Decode header & payload — splits your JWT into its three segments and displays each as formatted, syntax-highlighted JSON
- Check expiry — reads the
expandiatclaims and tells you at a glance whether the token is still valid or has expired - Verify signature — confirms the HMAC signature against your secret to prove the token hasn't been tampered with
- Encode & sign — build a custom header and payload, choose your algorithm, and generate a fully signed JWT for testing
- Colour-coded segments — header, payload, and signature are highlighted in red, purple, and blue — the same visual grammar developers recognise from jwt.io
- Privacy-first — all processing happens in your browser using the Web Crypto API; your tokens and secrets are never sent to any server
Decode JWT Tokens from Any Source
Use this tool to inspect JWTs from OAuth 2.0 flows, API gateway responses, identity providers, and microservice authentication headers. Whatever the source, paste it in to see the full claims immediately.
- OAuth 2.0 access tokens — inspect claims from Auth0, Okta, Cognito, Azure AD, and other identity providers
- Bearer tokens in API headers — decode tokens from Authorization headers when debugging REST or GraphQL APIs
- Refresh tokens — check expiry, issuer, and subject claims on long-lived tokens
- Service-to-service tokens — verify permissions and scopes for machine-to-machine authentication
- OIDC ID tokens — inspect user identity claims like
sub,email,name, andnonce
Who Uses an Online JWT Decoder?
Backend developers decode tokens to validate claims between microservices and debug auth flows. Frontend engineers inspect tokens from login responses to understand what user data is available. Security engineers verify signatures and check expiry to audit token handling. QA teams use the encoder to generate test tokens with specific claims for automated test suites.
About the JWT Decoder & Encoder
Key features
Decode header, payload & signature
Splits any JWT into its three parts and displays the header and payload as readable, indented JSON with full syntax highlighting.
Expiry check
Reads the exp and iat claims and instantly shows whether the token is still valid, expired, or has no expiry — with a time-remaining indicator.
Signature verification
Verifies HMAC signatures (HS256, HS384, HS512) against your secret using the Web Crypto API — entirely client-side, nothing transmitted.
Encode & sign
Build a custom header and payload, choose your algorithm, enter a secret, and generate a fully signed JWT for testing and development.
Who it's for
Backend developers
Inspect auth tokens from OAuth flows, API gateways, and microservice calls — quickly verify claims, scopes, and expiry without opening a debugger.
Frontend engineers
Decode access tokens from login responses to understand what user data is available and diagnose mismatches between token claims and UI behaviour.
Security & platform teams
Verify token signatures, audit expiry policies, and confirm algorithm choices during security reviews or incident investigations.
QA & test engineers
Encode custom tokens with specific claims — expired tokens, scoped permissions, edge-case payloads — to drive automated test suites without a live auth server.
Frequently Asked Questions
How does the JWT decoder work?
Simply paste your JWT into the box and the tool instantly splits it into its header, payload, and signature and displays the decoded claims as readable JSON — no button refresh needed.
Is this JWT decoder free to use?
Yes, it's completely free with no sign-up, downloads, or limits. Decode and encode as many tokens as you need, as often as you like.
Can it verify a token's signature?
Yes. You can verify a JWT's HMAC signature against a secret (for HS256, HS384, or HS512) to confirm the token hasn't been tampered with. Verification uses the browser's Web Crypto API entirely client-side.
Does it show when a token expires?
Yes. The tool reads the token's expiry (exp) and issued-at (iat) claims and tells you at a glance whether the token is still valid or has expired, including how much time remains or how long ago it expired.
Can I create and sign my own tokens?
Yes. Switch to the Encode tab, build a header and payload, provide a secret, and the tool will sign a valid JWT for testing using the Web Crypto API in your browser.
Which signing algorithms are supported?
The tool supports HMAC algorithms HS256, HS384, and HS512 for both signing and verification. Decoding works with any algorithm since it doesn't require the secret — you can decode an RS256 or ES256 token and inspect its claims without a key.
Are my tokens stored or sent anywhere?
No. Everything is decoded, verified, and signed entirely in your browser using the Web Crypto API. Your tokens and secrets are never stored or sent to a server, keeping sensitive credentials private.
Is it safe to paste a real token here?
Because all processing happens locally in your browser and nothing is transmitted, it's far safer than tools that send tokens to a server. Still, treat production secrets with care and avoid sharing them unnecessarily.
Does it work on mobile devices?
Yes, the tool is fully responsive and works on smartphones, tablets, and desktops without any installation.
What's the difference between decoding and verifying?
Decoding simply reads and displays a token's contents — anyone can do this with any JWT, no secret needed. Verifying checks the signature with a secret or key to confirm the token is authentic and hasn't been tampered with.