Female Tools  ·  JWT Decoder

JWT Decoder

Paste a JSON Web Token to decode its header and payload. This is a decoder, not a verifier — it does not check the signature, so a decoded token should never be trusted as authentic without server-side verification.

This jwt decoder is built for developers debugging authentication flows who need to quickly inspect what's actually inside a token. Paste any JSON Web Token and it splits the string on its dots, base64url-decodes the header and payload segments, and pretty-prints both as JSON. Standard registered claims — issuer, subject, audience, expiration, issued-at, not-before, and JWT ID — are pulled out into a separate readable list, with timestamp claims like exp and iat converted to human dates alongside their raw Unix values. You can copy the header or payload individually, or export both together as a Markdown snippet for bug reports and documentation. Because decoding happens entirely client-side, the token itself is never transmitted anywhere, which matters when you're working with real production credentials.

How to Use JWT Decoder

  1. Paste your JWT into the input field.
  2. Review the decoded header and payload, shown automatically as you type.
  3. Check the Standard Claims panel for issuer, subject, expiration, and other registered claims.
  4. Click "Copy" on either panel to copy just that section.
  5. Click "Copy as Markdown" to copy both header and payload formatted for documentation.

Frequently Asked Questions

Paste your JWT (the three dot-separated Base64 strings) into the JWT Decoder. It splits and decodes the header, payload, and signature instantly — no libraries needed.

Yes. Female Tools JWT Decoder runs entirely in your browser — the token is never sent to any server.

The JWT payload contains claims — key-value pairs like user ID, email, roles, and expiry time (exp). The decoder shows these in readable JSON.