Bidev

JWT Decoder

Paste a JSON Web Token to inspect its header and payload.

This tool only decodes the token — it does not verify the signature.

Related Tools

// more about this tool

What gets decoded, and what doesn't

A JWT has three Base64Url-encoded segments separated by dots: a header, a payload, and a signature. This tool decodes the header and payload back into readable JSON so you can inspect the claims (expiry, subject, custom fields) directly. It does not, and cannot, verify the signature, since that requires the secret or public key the token was signed with, which never leaves your auth server.

A decoded token is not a verified token

This is worth stating plainly: anyone can decode a JWT and read its contents, including an attacker holding a token they didn't legitimately receive. Decoding tells you what a token claims; it says nothing about whether those claims are trustworthy. Verification always has to happen server-side, against the actual signing key, before you trust anything in the payload.

Common debugging use

Checking why a token is being rejected as expired (the exp claim is a Unix timestamp, easy to misread), confirming which claims your auth provider actually included, or comparing a token issued in dev against one from production when something behaves differently between environments.