JWT encoder / decoder
Decode JWT headers and payloads, inspect common claims, and create signed or unsigned tokens with custom header, payload, and secret input.
About this tool
A JSON Web Token is three base64url-encoded segments joined by dots: a header naming the signing algorithm, a payload carrying claims, and a signature over the first two. The encoding is not encryption. Anyone holding a token can read its payload, which is why a JWT should never carry a password, a full card number, or anything else you would not put in a log line. You meet them constantly — as the bearer token in an Authorization header, as the id_token that comes back from an OAuth 2.0 or OpenID Connect flow, in session cookies, and in service-to-service calls inside a cluster. Most debugging comes down to reading the payload: has exp already passed, is iss the issuer you expect, does aud name your API, does the sub match the user you think is calling. This tool splits a token into its three parts and pretty-prints the header and payload, and it can mint signed HS256 tokens or unsigned ones for test fixtures. Decoding happens in your browser; nothing you paste is uploaded.
- 1
Paste a JWT token (the three-part dot-separated string) into the input field.
- 2
The tool instantly decodes and displays the header, payload, and signature in separate panels.
- 3
Check the payload for claims like exp (expiry), sub (subject), and iss (issuer).
- 4
Note: this tool decodes — it does not verify the signature. Never trust a JWT without server-side verification.
Inspect copied bearer tokens from API requests, logs, or auth middleware.
Decode header and payload claims without sending the token to a server.
Review issued-at and expiry claims when debugging session problems.
Decode a JWT header
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9{"alg":"HS256","typ":"JWT"}Decode a JWT payload
eyJzdWIiOiJ1c2VyXzEyMyIsImlhdCI6MTcwMDAwMDAwMCwiZXhwIjoxNzAwMDM2MDAwfQ{"sub":"user_123","iat":1700000000,"exp":1700036000}Invalid token — expected 3 parts
Cause: The string is missing a segment or was truncated in transit. A common culprit is copying an Authorization header value and bringing the Bearer prefix along with it, or a token wrapped across lines by a terminal.
Fix: Paste only the token itself, starting at eyJ and with no Bearer prefix, whitespace, or line breaks. A valid JWT has exactly two dots.
Payload decodes to garbage or fails to parse as JSON
Cause: The token is base64url-encoded, not standard base64, and something in the pipeline re-encoded it. URL-encoding the token turns the segments into %2E-separated text, and some tools swap - and _ back to + and /.
Fix: Decode the URL-encoding first, then paste the raw token. If you extracted the token from a query string or a cookie, run it through the URL decoder before pasting it here.
Token looks fine but the API still returns 401
Cause: Decoding is not verifying. A structurally valid token can still be expired, signed with the wrong key, or issued for a different audience — none of which decoding will reveal.
Fix: Check exp against the current epoch time, confirm iss and aud match what your API expects, and verify the signature server-side with the issuer's secret or public key. Clock skew between your server and the issuer is a frequent cause of tokens that look valid but are rejected.
These answers explain common jwt encode/decode tasks, expected input formats, and edge cases so both visitors and search engines can understand what this tool does.
Does this JWT inspector verify the token signature?
No. This tool decodes the token header and payload for inspection. It does not validate the signature or confirm that the token was issued by a trusted source.
Can this tool create a signed JWT?
Yes. The encoder can generate JWTs using HMAC algorithms such as HS256, HS384, and HS512 when you provide a secret. It can also create unsigned tokens when the header alg is set to none.
What parts of a JWT does this tool show?
It shows the decoded header and payload, plus common summary fields such as algorithm, issuer, subject, audience, and time-based claims when they are present.
Can I inspect expired JWTs?
Yes. Even an expired token can still be decoded and inspected. The decoded payload helps you review the exp, iat, and nbf claims when debugging auth issues.
Should I paste production secrets into a JWT tool?
Only if you trust the tool and your environment. This app runs in the browser, but sensitive tokens should still be handled carefully and only when necessary.
The jsonwebtoken package is the standard Node.js JWT library. Use jwt.sign to create tokens and jwt.verify to validate them.
// npm install jsonwebtoken
const jwt = require("jsonwebtoken");
const secret = "my-secret-key";
const payload = { userId: 42, name: "Alice", role: "admin" };
// Sign (encode) — HS256 is the default algorithm
const token = jwt.sign(payload, secret, { expiresIn: "1h" });
console.log(token);
// eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
// Verify and decode
try {
const decoded = jwt.verify(token, secret);
console.log(decoded);
// { userId: 42, name: 'Alice', role: 'admin', iat: ..., exp: ... }
} catch (err) {
if (err.name === "TokenExpiredError") console.error("Token expired");
else console.error("Invalid token:", err.message);
}
// Decode without verifying (inspect header/payload only)
const unverified = jwt.decode(token, { complete: true });
console.log(unverified.header); // { alg: 'HS256', typ: 'JWT' }
console.log(unverified.payload);See full JavaScript / Node.js examples →