Developer tools

JWT Decoder

Decode the header and payload of a JSON Web Token locally, inspect its timestamps, and keep the important distinction between reading a token and verifying its signature.

Inspect a JSON Web Token

Header

Payload

Inspect harmless claims

The sample contains alg=none, a fictional subject, and an expired timestamp. It is deliberately not a usable login token. Use Decode to inspect it, and keep the signature-not-verified warning beside the result.

Input or checkExpected result or decision
sub: demo-userA claim made by the sample, not proof of a user's identity.
exp: 0An expired timestamp at the Unix epoch.
A readable header and payloadNo signature, issuer, audience, or authorization validation has been established.
Malformed synthetic token: abc.defError: A compact JWT must contain a header, payload, and signature section. Earlier output is cleared.

How it works

  • Paste a compact JWT containing three dot-separated sections.
  • The first two Base64URL sections are decoded as UTF-8 JSON.
  • Expiration and not-before timestamps are shown relative to the current time when present.

Common uses

  • Inspecting claims during authentication debugging.
  • Checking issuer, audience, subject, and expiry values.
  • Confirming whether a token’s payload contains the expected fields.
Your input stays in this browser. Nothing entered into this tool is sent to the Anvil Tools server.

A practical walkthrough

  1. Paste a test JWT to inspect its header and payload, then compare the claims with the values your application expects.
  2. Read issuer, audience, and expiry together. A readable payload alone does not prove that the token is authentic.
  3. Inspect the header, payload and date notes. Use Clear when finished; decoding does not verify the signature.

Tips for a reliable result

The tool does not verify signatures. Use your authentication library on the server to verify a token before trusting its claims.

What to use next

These tools open separately; inputs are not transferred.

Developer tools

Unix Timestamp Converter

Convert Unix seconds or milliseconds to readable local and UTC dates.

Open tool →
Developer tools

JSON Formatter & Validator

Pretty-print, minify, and validate JSON directly in your browser.

Open tool →
Developer tools

Base64 Encoder & Decoder

Convert text to Base64 and back, entirely in your browser.

Open tool →
Developer tools

CSV to JSON Converter

Convert quoted CSV data into JSON arrays or objects locally.

Open tool →

How this tool handles your data

The token header and payload are decoded in your browser. The token is not uploaded to an Anvil processing server.

Compare privacy behavior across all tools.

Known limitations

Decoding does not verify a signature, issuer, audience, expiry policy, or trust. A readable token can still be forged or invalid.

Related guide and Lab test

Questions and troubleshooting

Does decoding verify the token?

No. Anyone can decode a JWT. Trust it only after a server verifies the signature, accepted algorithm, issuer, audience, and relevant time claims.

Is the token uploaded?

No. Decoding happens entirely in your browser. Avoid sharing live access tokens with other people or services.

When a token cannot be inspected

Remove a copied Bearer prefix and check that the sample has the expected dot-separated structure. Encrypted tokens require a different workflow. Use a harmless development token for support; successful decoding still does not verify the signature or grant access.

Can I edit a decoded claim to gain access?

Changing a payload does not produce a valid signed token. A correctly configured server verifies the signature and claims before accepting it.

Is a JWT payload encrypted?

An ordinary signed JWT exposes readable header and payload data. This tool handles compact three-part tokens, not encrypted JWE messages. Never paste a live token into a support request.

Read the practical guide

Debug API Data with JSON, Base64, and Browser Tools

Work through JSON types, encoding, URL components, JWT claims, hashes, CSV conversion, and timestamps with small reproducible examples.