JWT Decoder
Decode JWT headers, payload JSON, algorithm headers, and expiration claims 100% locally in your browser. Fast, secure, and private.
Recently Used Tools
Understanding JSON Web Tokens (JWT)
JSON Web Tokens (JWT) are an open, industry-standard (RFC 7519) method for securely representing claims between two parties. They are widely used in modern web applications for user authentication, session management, and API authorization. A standard JWT consists of three distinct parts separated by dots (.): the Header, the Payload, and the Signature.
1. The Header
The header typically consists of two parts: the type of token (which is JWT) and the cryptographic signing algorithm being used, such as HMAC SHA-256 (HS256) or RSA (RS256). This JSON object is then base64url encoded to form the first part of the token.
2. The Payload
The payload contains claims—statements about an entity (typically, the user) and additional data. Claims are categorized into registered claims (such as iss for issuer, exp for expiration time, sub for subject, and aud for audience), public claims, and private custom claims defined by your application. Like the header, the payload is Base64URL encoded.
3. The Signature
To create the signature part, the encoded header, encoded payload, a secret key, and the algorithm specified in the header are passed through a cryptographic hash function. The signature is used to verify that the sender of the JWT is who it says it is and to ensure that the message was not tampered with along the way.
Why Local Client-Side Decoding Matters
Because JWT payloads frequently contain user IDs, authorization roles, email addresses, and session expiration timestamps, sending your production or staging JWT tokens to external server endpoints poses a privacy risk. FreeFileTool's JWT Decoder runs 100% inside your local browser tab, guaranteeing that your authorization tokens never leave your machine.
Frequently Asked Questions
Is it safe to paste my JWT tokens into this decoder?
Yes, 100%. FreeFileTool decodes JSON Web Tokens entirely inside your browser's local memory using pure JavaScript base64url parsing. Your token is never uploaded or sent across any network.
Does this tool verify the JWT signature?
This tool decodes and displays the unencrypted Header and Payload metadata contained within the JWT. Signature verification requires the private key or secret key which remains on your authentication backend server.
How are JWT timestamps formatted?
Standard JWT claims like exp (expiration), iat (issued at), and nbf (not before) are stored as Unix epoch timestamps (seconds since Jan 1, 1970). Our tool converts these numeric values into readable ISO and local time strings automatically.
What is base64url encoding in JWTs?
JWTs use Base64URL encoding, which is a variant of Base64 that replaces '+' with '-' and '/' with '_' while omitting trailing '=' padding characters to ensure tokens can be safely transmitted in HTTP headers and URL parameters.