Skip to content

JWT Decoder & Inspector

Decode JSON Web Tokens to inspect the header, algorithm, standard and custom claims, readable timestamps and expiration status.

JWT Decoder & Inspector

340 chars

Token decoded, algorithm HS256

Algorithm:HS256
HeaderJOSE header
{
  "alg": "HS256",
  "typ": "JWT"
}
PayloadClaims set
Registered claims
iss(Issuer)
autonomous-factory
sub(Subject)
1234567890
aud(Audience)
hub.users
exp(Expiration Time)
2016239022
2033-11-22 02:23:42 UTC
nbf(Not Before)
1516239022
2018-01-18 01:30:22 UTC
iat(Issued At)
1516239022
2018-01-18 01:30:22 UTC
jti(JWT ID)
a5c3f1b8-7d64-4e2a-9e1b-3c8f0b2a1d7e
Custom claims
nameJohn Doe
roleadmin
Raw JSON
{
  "sub": "1234567890",
  "name": "John Doe",
  "iat": 1516239022,
  "exp": 2016239022,
  "iss": "autonomous-factory",
  "aud": "hub.users",
  "jti": "a5c3f1b8-7d64-4e2a-9e1b-3c8f0b2a1d7e",
  "nbf": 1516239022,
  "role": "admin"
}
SignatureHS256
Hex
49f94ac7044948c78a285d904f87f0a4c7897f7e8f3a4eb2255fda750b2cc397

What this tool does

You can decode a JWT and read its header, payload claims, and expiration without sending the token anywhere: the decoder splits the three base64url segments and parses them entirely in your browser. Registered claims (iss, sub, aud, exp, nbf, iat, jti) are labeled, and exp is converted into a live expired-or-not countdown. Decoding does not verify the signature — no secret or key is involved.

Updated . Provided as is. Check the output before you rely on it in production.

How to use JWT Decoder & Inspector

  1. 1

    Paste your JWT token

    Copy a JSON Web Token from your auth system (usually from Authorization header or localStorage) and paste it into the decoder.

  2. 2

    View decoded header and payload

    See the token's header (algorithm, type), payload (claims like sub, exp, iat), and signature. All three parts are decoded and displayed separately.

  3. 3

    Check expiry and validate claims

    Look at the `exp` (expiration) claim to see when the token expires. Check `iat` (issued at) and other claims to understand token validity.

  4. 4

    Read the signature segment

    The third segment is shown decoded to hex alongside the header's algorithm. Decoding never checks the signature, so treat any claim in the payload as unverified until your backend validates the token.

  5. 5

    Inspect custom claims

    Review all custom claims (roles, permissions, user ID, etc.) in the payload. Use this to debug auth issues and understand token contents.

Questions and answers

What is JWT Decoder & Inspector?
A JSON Web Token (JWT) is a base64url-encoded header, JSON payload of claims and signature, used to carry identity between services. This decoder shows the algorithm, labels standard claims such as iss, sub and exp, converts timestamps to dates, and says whether the token has expired. It does not verify signatures.
Does JWT Decoder & Inspector store or send my data?
No. All processing happens entirely in your browser. Your JWT never leaves your device — nothing is sent to any server. This makes it safe for inspecting production tokens.
Can it verify JWT signatures?
The tool decodes and displays the header and payload without needing a secret key. Signature verification would require your secret or public key, so the tool focuses on safe, client-side inspection of token structure, claims, and expiration.

Use it as an API

JWT Decoder & Inspector is also callable as a free HTTP JSON API at https://aidevhub.io/api/jwt-decoder/ — GET with query parameters or POST with a JSON body, no authentication, CORS enabled, fair use (abusive traffic is throttled at the edge; there is no per-request quota header). Responses return { ok, tool, result, meta }.

curl -s "https://aidevhub.io/api/jwt-decoder/?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c"

Machine-readable contract: /api/tool/jwt-decoder.json All API endpoints: /agents/ LLM site index: /llms.txt

For AI agents: how to call this tool

Machine-readable contract, endpoints and examples. Humans can ignore this section.

Best Path For Builders

Dedicated API endpoint

Deterministic outputs, machine-safe contracts, and production-ready examples.

Dedicated API

https://aidevhub.io/api/jwt-decoder/

OpenAPI: https://aidevhub.io/api/openapi.yaml

GET /api/jwt-decoder/ GET jwt-decoder
POST /api/jwt-decoder/ POST jwt-decoder

How do I decode a JWT and inspect its claims?

Paste the token into the input. A JWT is three base64url-encoded segments joined by dots — header.payload.signature — and the first two are plain JSON that anyone can decode without a key. The decoder validates the structure, parses header and payload, labels the registered claims, converts the timestamp claims into readable dates, and shows the signature bytes as hex.

Step by step

  1. Paste the full token (or press Sample JWT to see the format). Malformed tokens get a specific error: wrong segment count, invalid base64url characters, or non-JSON content.
  2. Read the header: the alg value is shown with its meaning (for example HS256 = HMAC using SHA-256).
  3. Read the payload: registered claims are listed with labels, custom claims separately, and the raw JSON below.
  4. Check the expiration badge — exp is compared against the current time and shown as a countdown or an "expired ago" notice.
  5. Copy header, payload, or signature hex out with one click.

JWT registered claims reference (RFC 7519)

Claim Name Meaning
iss Issuer Who created and signed the token.
sub Subject Who the token is about — typically the user ID.
aud Audience Which service the token is intended for; recipients must reject tokens aimed elsewhere.
exp Expiration Time Unix timestamp (seconds) after which the token must be rejected.
nbf Not Before Unix timestamp before which the token is not yet valid.
iat Issued At Unix timestamp of when the token was created.
jti JWT ID Unique token identifier, used to detect replay or support revocation lists.

The seven registered claim names from RFC 7519 section 4.1 — the set this decoder labels. All are optional; anything else in the payload is shown under custom claims.

Does decoding a JWT verify its signature?

No, and that distinction matters. The header and payload are only base64url-encoded, not encrypted, so decoding proves nothing about authenticity. Verification requires recomputing the signature with the issuer's secret (HS*) or public key (RS/ES/PS/EdDSA) — something a server must do before trusting any claim. This tool is an inspector: it shows what a token says, including tokens signed with alg: none, which any verifier should reject outright.

Why does my token show as expired?

exp is seconds since the Unix epoch, compared against your system clock. If a fresh token reads as expired, check for a milliseconds-vs-seconds mix-up on the issuing side (a millisecond value in exp lands tens of thousands of years in the future, while a truncated one reads as 1970) and for clock skew between issuer and verifier.

Is it safe to paste a live token into this page?

Decoding runs entirely in your browser; the token is never transmitted, stored, or logged. Still, treat any bearer token that has touched a clipboard as sensitive — it grants access until exp. Prefer inspecting expired or test-environment tokens, and rotate any production token you suspect has leaked.