APILens open source
Full tool ↗ GitHub ↗

JWT Decoder — decode any JSON Web Token

Paste a JWT to read its header, payload and signature. Claims like exp, iat, sub and aud are shown as readable dates. Everything is decoded locally in your browser — your token never leaves your machine.

Decoded header, payload and signature appear here.

JWT decoder — frequently asked questions

Does this JWT decoder verify the signature?

No. A JWT's header and payload are only Base64URL-encoded, not encrypted, so anyone holding the token can read them. Verifying the signature requires the signing secret or public key, which this client-side decoder does not ask for. Watch for alg: none — it's a classic vulnerability flag.

Is it safe to paste my JWT here?

Yes — decoding happens 100% in your browser; nothing is uploaded, logged or transmitted. Still, avoid pasting production tokens into any shared screen.

What do exp and iat mean?

exp is the expiration time and iat the issued-at time, both as Unix timestamps in seconds. This decoder converts them to readable dates and flags a token whose exp has already passed.

Why can anyone read my JWT payload?

JWTs are signed, not encrypted. The payload is only Base64URL-encoded, so it is readable by design — never put secrets, passwords or PII in a JWT payload.

What is a JWT?

A JSON Web Token (RFC 7519) is three Base64URL parts joined by dots: header.payload.signature. The header names the algorithm, the payload holds the claims, and the signature verifies the token hasn't been tampered with.

Is there a Chrome extension?

Yes — APILens also ships as an open-source Chrome (MV3) extension. Both are MIT-licensed on GitHub, and the full tool adds JSON formatting, diff and JSONPath.