JWT Decoder & Validator

Decode, validate, and inspect JSON Web Tokens (JWT). Parse header, payload, verify signatures with HMAC algorithms, and check token expiration: all client-side.

JWT Decoder & Validator

Decode, validate, and inspect JSON Web Tokens

Length: 0

About JWT

What is a JWT Decoder?

A JWT decoder is a tool that parses and displays the contents of a JSON Web Token (JWT). JWTs are the most widely used authentication tokens in modern web applications: used by OAuth 2.0, OpenID Connect, and stateless REST APIs. They consist of three Base64URL-encoded parts: a header describing the algorithm, a payload containing claims (user data and metadata), and a signature for verification.

CodeHelper's JWT Decoder & Validator decodes tokens instantly and can verify HMAC signatures (HS256, HS384, HS512) entirely in your browser, so your tokens never leave your machine.

JWT Claims Explained

  • exp: Expiration time: the token is invalid after this UNIX timestamp.
  • iat: Issued at: when the token was created.
  • sub: Subject: typically the user ID the token represents.
  • iss: Issuer: the entity that created the token (e.g., your auth server URL).
  • aud: Audience: the intended recipient(s) of the token.
  • nbf: Not Before: the token is not valid before this time.

How to decode a JWT token

  1. Paste your JWT token (starting with "eyJ...") into the input field.
  2. The header and payload are decoded and displayed as formatted JSON instantly.
  3. Review token claims, expiration status, and time remaining.
  4. Optionally enter your HMAC secret to verify the signature.
  5. Copy individual parts for use in debugging or documentation.

Whether you are debugging authentication issues, inspecting OAuth tokens, auditing API security, or learning how JWTs work, this free JWT decoder and validator is the most private and convenient tool available.

Looking for an identity provider to issue these tokens? Compare authentication APIs such as Auth0 and Stytch, with their free tiers, in the API directory.

Frequently Asked Questions

What is a JWT token?

A JWT (JSON Web Token) is a compact, signed token used to transmit identity and claims between systems, typically for API authentication and OAuth flows. It has three base64url-encoded parts separated by dots: a header (algorithm), a payload (claims like user id and expiration) and a signature that lets the receiver verify the token was not tampered with.

Is it safe to paste a JWT into an online decoder?

Only if the decoding happens in your browser. A JWT often contains user identifiers and, until it expires, can authenticate requests, so pasting it into a server side tool means sharing a live credential. This decoder runs entirely client side: the token never leaves your machine. Even so, prefer decoding expired or development tokens over production ones.

Can I decode a JWT without knowing the secret?

Yes. The header and payload are just base64url-encoded JSON, readable by anyone: no secret is needed to see the claims. The secret or key is only required to verify the signature, that is, to prove the token was issued by the expected party and not modified. This is why a JWT should never contain data that must stay confidential.

Why is my JWT invalid or expired?

The most common causes: the exp claim is in the past (token expired), the signature does not match because the wrong secret or algorithm is used for verification, the token was truncated when copied, or the clock of the issuing and verifying servers disagree. Paste the token here to inspect exp, iat and the algorithm in the header, which resolves most of these in seconds.

Free forever, no ads, no tracking. Support the project