Read a JSON Web Token header, payload and claims. Never uploaded.
Paste a JWT above to decode it.
Bearer prefixes, quotes, and wrapped tokens are cleaned automatically.
Not verified. Checking the signature requires the secret or public key.
Runs entirely on your device. Nothing is uploaded. Your token is never sent to any server.
▸ More about
Uses of JWT
- Inspecting the claims in an auth token while debugging a login flow
- Checking whether an access token has expired
- Reading the issuer and audience of a token from a third-party API
- Confirming which algorithm a token was signed with
JWT pitfalls
- Believing a JWT payload is encrypted or private
- Treating a successful decode as proof the token is valid
- Storing passwords or secrets inside the payload
JWT questions (11)
Is it safe to paste my JWT here?
Yes. This tool runs entirely in your browser. The token is decoded with local JavaScript and is never uploaded, logged, or sent to any server. ToyTools is a static site with no backend, so there is nowhere for your token to go. That said, treat any token you copy from other systems as a secret and avoid pasting it into tools you do not trust.
What is a JWT made of?
A JWT has three parts separated by dots: the header, the payload, and the signature. The header and payload are JSON objects encoded with Base64URL, so anyone can decode and read them. The signature is a cryptographic value that lets a server confirm the token was not tampered with. This tool decodes the header and payload and shows the raw signature.
Does this tool verify the signature?
No. Decoding and verifying are different operations. Decoding just Base64URL-decodes the header and payload so you can read them, which needs no key. Verifying checks the signature against the secret (for HMAC) or the public key (for RSA or ECDSA) to prove the token is authentic and unmodified. Signature verification must happen on your server with the key, never in a public web tool.
What do exp, iat, and nbf mean?
These are registered time claims, expressed as Unix timestamps in seconds. "iat" (issued at) is when the token was created. "exp" (expiration) is when it stops being valid. "nbf" (not before) is the earliest time the token may be used. This tool converts each of these to a readable date and a relative time, and flags the token as expired when "exp" is in the past.
Can a JWT be decrypted?
A standard JWT is not encrypted, so there is nothing to decrypt. The header and payload are only encoded, which means anyone can read them. Never store passwords or other secrets in a JWT payload. If you genuinely need the contents hidden, you want a JWE (JSON Web Encryption) token, which is a different format.
Why does my token fail to decode?
The most common causes are a missing or extra segment (a valid JWT has exactly three dot-separated parts), copied whitespace or line breaks inside the token, or a truncated value. This tool reports the specific problem, such as an invalid Base64URL segment or a payload that is not valid JSON, so you can pinpoint the issue.
What is the difference between Base64 and Base64URL in a JWT?
JWTs use Base64URL, a variant of Base64 that replaces "+" with "-" and "/" with "_" and drops the trailing "=" padding. This makes the encoded segments safe to place directly in URLs and HTTP headers without further escaping. This decoder restores the standard characters and padding automatically before decoding.
Can I edit a decoded token and re-sign it?
Not with this tool. You can read and copy the decoded header and payload, but changing the payload would invalidate the signature, and re-signing requires the original secret or private key. Issuing or signing tokens should be done by your authentication server, not a browser tool.
Can I decode a JWT in the browser without uploading it?
Yes. The header and payload are decoded in your browser. The token is not sent to a server for decoding.
Does decoding a JWT mean the token is trusted?
No. This page reads the header and payload. It does not check the signature, so a decoded token is not proof that anyone issued it.
Is the JWT Decoder an AI tool?
No. It does not call a model. You can copy a decoded payload into a model yourself. ToyTools does not do that.