JWT Decoder
Decode a JWT token's header and payload online, free and instantly. Paste a token — with or without a Bearer prefix — into the live tool below and read its claims as formatted JSON. No signature verification.
About this tool
- What is it?
- DataFormatter JWT Decoder is a free online tool that decodes a JWT's header and payload into readable JSON, handling Bearer prefixes automatically.
- Who is it for?
- Developers and testers inspecting access tokens, verifying claims or debugging auth flows without exposing token contents to a third-party service.
- What makes DataFormatter's tool different?
- Decoding is 100% local — tokens are never sent to a server — and it auto-strips Bearer prefixes so you can paste a token as-is.
Manual tool: JWT Decode — auto-detection is disabled.
Input
0 chars · 0 words · 0 linesPaste or type JSON, Base64, or plain text…
Paste or click a sample above — it will be detected automatically.
Quick start
- Paste the token above — a leading 'Bearer ' is stripped automatically.
- Header and payload appear as formatted JSON sections.
- Copy individual claims straight from the output for your bug report.
How JWT decoding works
A JSON Web Token (JWT) is composed of three base64url parts joined by dots: header.payload.signature. The header describes the signing algorithm (for example HS256), and the payload holds the claims — the identity and attributes of the token (such as sub, name, iat, and exp).
This decoder reads those base64url segments, decodes them as UTF-8 JSON, and renders the header and payload as pretty-printed JSON so you can inspect a token quickly. The signature segment is surfaced as-is; it is never decoded to text and no cryptographic verification is performed.
eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjM0NSIsIm5hbWUiOiJKb2huIn0.signature{
"alg": "HS256"
}
---
{
"sub": "12345",
"name": "John"
}How to decode a JWT online
- Paste the token — with or without a 'Bearer ' prefix — into the editor above.
- The header and payload appear as formatted JSON sections.
- Tokens embedded inside surrounding text are detected automatically.
- Copy or download the decoded claims for your bug report.
Debugging auth flows with decoded tokens
Checking what an API issued you
Paste an access token to see its scopes, roles and expiry before blaming your request headers for that mysterious 403.
OAuth / OpenID Connect setup
Inspect ID tokens during client configuration to confirm issuer, audience and claim mapping match what your code expects.
Security reviews
Understand exactly which attributes applications can read from a token — and confirm nothing sensitive is riding along in the payload.
Common JWT decoding errors
Unexpected token or malformed JSON after decodingWhy: The token was truncated during copy-paste — most often the final signature segment or the last character of the payload.
Fix: Re-copy the entire three-part token from its source and make sure no line breaks were inserted.
Decoded payload shows %22 or %7B sequencesWhy: The token passed through URL-encoding somewhere in transit (logs and query strings often do this).
Fix: Decode once with the URL Decoder first, then paste the clean token here.
Signature says 'invalid' in my backend but decodes fine hereWhy: That's expected: decoding always succeeds because the payload is plain base64url, not encrypted. Signature verification requires the secret or public key server-side.
Fix: Check key choice (HS vs RS family), issuer and audience values in your verification library instead.
Decoding vs verifying
Anyone can decode a JWT — the payload is merely encoded, not encrypted. Verifying a token requires its secret or public key so the signature can be checked server-side. Use this tool to inspect tokens during development; always verify signatures in your application before trusting any claim.
Pro tips
- Need the raw segments separately? The Base64 Decoder handles base64url directly for one-off segment inspection.
- Verify checksums of signed artifacts with the Hash Generator while you're debugging auth integrations.
- Split view keeps the original token and decoded claims on screen together — ideal when writing up findings.
- Download the decoded claims to attach structured evidence to security tickets.
JWT glossary
- Claim
- A named piece of information inside a JWT payload, such as sub (subject), iss (issuer) or exp (expiry). Claims are statements about the user or token — but they are only trustworthy after the signature has been verified.
- base64url
- The URL-safe Base64 variant JWTs use: - replaces + and _ replaces /. It lets tokens travel inside HTTP headers and query strings without extra escaping.
Frequently asked questions
What does a JWT decoder show?
A JWT is three base64url segments: header, payload, and signature. The decoder shows the decoded header (says the algorithm such as HS256) and payload (the claims, like sub, name, and exp) as readable JSON.
Does this decoder verify token signatures?
No. Like diagnostic JWT tools, it decodes the header and payload for inspection but does not verify the signature. Decoding is not verification — never trust the claims of an unverified token.
Is it safe to paste a JWT here?
Yes from a privacy standpoint — decoding happens locally in your browser and nothing is uploaded. Still avoid pasting live production tokens containing sensitive claims.
Why does my token say 'Invalid' or fail to decode?
Most failures are truncated tokens (a dot or final segment lost during copying), URL-encoded characters inside the token, or text that isn't a JWT at all. Re-copy the complete three-part token and retry.
What do the exp and iat claims mean?
They are Unix timestamps: iat is when the token was issued, exp is when it expires. Convert them with any epoch converter to see the times in your timezone.
Can I decode a token without the signature part?
Often yes — some tools accept header.payload only. This decoder follows the standard three-segment format; if you only have two segments, try appending a placeholder third segment separated by a dot.