Free Tool
Free JWT Inspector
Paste a JWT to instantly decode its header and payload.
Free, private, no upload to a server. Everything happens in your browser.
Your token is never sent anywhere — decoding happens entirely in your browser.

This tool only DECODES — it does NOT verify the signature
Decoding just reads the token's base64 + JSON contents. It does not check the cryptographic signature, so a token that decodes successfully is not proof it is authentic, unmodified, or was actually issued by whoever it claims. Never treat "decodes fine" as "valid" or "verified" — only real signature verification (with the correct secret or public key, on a server) can prove that.
JWT (header.payload.signature)
Registered Claims
Subject (sub)
"1234567890"
Issued At (iat)
1516239022 — Thu, 18 Jan 2018 01:30:22 GMT
Header (decoded)
Payload (decoded)
Signature Segment (raw — not verified)
SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
Everything You Need to Inspect a JWT
100% Private
Your token is never sent anywhere — decoding happens instantly in your browser.
Completely Free
No sign-up, no limits. Free forever.
Full Decode
Correctly base64url-decodes and pretty-prints both header and payload.
Claim Highlights
iss, sub, aud, exp, iat, and nbf get human-readable dates automatically.
Expiry Check
Instantly see whether a token has expired, and how long ago.
No False Confidence
Never claims a token is "valid" — decoding is not the same as verifying.


