---
title: "JWT Decoder"
description: "Decode a JSON Web Token's header and payload instantly. Runs entirely in your browser — the token is never sent anywhere."
url: "https://freshjuice.dev/tools/jwt-decoder/"
---
## About this tool

Paste a JWT and the header and payload are decoded from Base64URL and pretty-printed as JSON. Handy for inspecting claims like`exp`, `iat`, `sub`, and`scope` while debugging auth flows.

**Decoding is not verification.** Anyone can decode a JWT — the signature is what proves it was issued by a trusted party. This tool does not verify signatures (that requires the issuer's secret or public key); it only shows you what's inside.

## JWT anatomy

-   **Header** — algorithm (`alg`) and token type.
-   **Payload** — the claims: issuer, subject, expiry, custom data.
-   **Signature** — HMAC or asymmetric signature over the first two parts.

Everything runs locally via `atob` and`TextDecoder` — nothing leaves your device, so it's safe to paste production tokens here.

## Frequently Asked Questions

### Is it safe to paste a real token here?

Yes. Decoding runs entirely in your browser via `atob` and `TextDecoder`. No network request, no logging, no storage. Open the Network tab and paste a token if you want proof: nothing goes out. Using a test token is still better hygiene when you have one.

### Can this tool verify a JWT's signature?

No, and that's by design. Verifying a signature requires the issuer's secret (HMAC) or public key (RSA/EC), and only the issuer has those. This tool decodes: it shows what's inside the header and payload so you can inspect claims like `exp`, `iat`, `sub`, and `scope` while debugging. Verification belongs in your application code, where the keys live.

### Why is my payload showing weird characters or empty?

JWT payloads are Base64URL-encoded JSON without padding. If the JSON is malformed or you truncated the token during copy-paste, decoding fails or produces garbage. Copy the full token, all three dot-separated parts, with no surrounding whitespace.

### What's the difference between a JWT's signature and its payload?

The payload is the readable part: claims like issuer (`iss`), expiry (`exp`), subject (`sub`), and any custom data. Anyone can decode it; it's encoded, not encrypted. The signature is the cryptographic proof that the token came from whoever holds the secret and wasn't modified in transit. Decoding shows you the claims. The signature tells you whether to trust them.

### Can it decode refresh tokens or opaque tokens?

No. It handles JWTs only: tokens with three dot-separated Base64URL parts (`header.payload.signature`). Opaque tokens (random strings with no internal structure) and session cookies have nothing to decode. If your token has no dots, it isn't a JWT.

### Does the token expire? What does the exp claim mean?

`exp` is the expiration time as a Unix timestamp in seconds. After that moment, conforming libraries reject the token. Related claims: `iat` (issued at) and `nbf` (not before). To see the human-readable date, paste the value into our [Unix timestamp converter](https://freshjuice.dev/tools/timestamp-converter/).
