Base64 Decoder
Decode Base64 back to text, with friendly errors for malformed input.
Read the header and payload of a JSON Web Token.
A leading Bearer prefix and any whitespace are ignored.
This tool decodes only. It never verifies the signature, because that would require your signing key, and a signing key should never be pasted into a web page.
A JSON Web Token is three Base64-encoded sections separated by full stops: a header saying how it was signed, a payload of claims, and a signature. The first two are encoded, not encrypted, which means anyone holding a token can read what is inside it. This tool does exactly that, and shows the result as formatted JSON.
Timestamp claims are the ones people most often need. The decoder converts issued-at, not-before and expiry into readable dates and tells you whether the token has expired and by how long. The standard registered claims are also labelled, so you can see at a glance which value is the subject, the issuer and the audience.
One thing this tool deliberately does not do is verify the signature. Verification requires the secret or public key, and pasting a signing secret into a web page is exactly the habit that leads to leaked credentials. Decoding tells you what a token says; only your server, holding the key, can tell you whether to believe it.
The jwt decoder is used by writers, developers, students, marketers and anyone else who needs the job done once without installing software. Common cases include:
No, and that is deliberate. Verification needs the signing secret or public key, and pasting a secret into a web page is a bad habit regardless of who runs the page. Decoding shows what a token claims; only a server holding the key can confirm it was really issued.
No. The header and payload are Base64-encoded, which is reversible by anyone. Never put a password, a card number or any other secret in a token payload, because every holder of the token can read it.
Expiry, issued-at and not-before. All three are Unix timestamps in seconds, which is why they look like meaningless numbers until converted. The decoder shows the readable date beside each one.
A JWT has exactly three sections separated by full stops. If a section is missing or a character was lost when copying, decoding stops. Tokens are often truncated when copied out of a log or a terminal window.
Decoding happens entirely in your browser and the token is never transmitted. Even so, treat a live token like a password: if it has been shared somewhere you do not control, have it revoked.
The third section is shown as raw text. It is a binary value rendered in URL-safe Base64, so it will not look like anything readable, and it cannot be checked without the key.
If the jwt decoder is not quite what you need, these other free tools solve closely related problems.
Decode Base64 back to text, with friendly errors for malformed input.
Pretty-print and validate JSON, with the exact line and column of any error.
Generate cryptographic hashes of text, computed in your browser.
Translate between Unix time and human-readable dates in both directions.
Decode %20 and other percent escapes back into normal characters.