Developer & Text Tools

JWT Decoder

Decode JWT headers, payload JSON, algorithm headers, and expiration claims 100% locally in your browser. Fast, secure, and private.

100% Private · Runs locally in your browser 0 KB Uploaded
1

Selected in Browser Memory

When you select or drop a file, your browser creates a temporary local Blob / ArrayBuffer pointer directly in your device's RAM.

2

Processed Client-Side

Our client-side engine (HTML5 Canvas & Client JavaScript) processes the data directly using your computer or phone's CPU.

3

Saved Directly to Your Downloads

The resulting output is downloaded immediately to your device. When you close or refresh the tab, memory is cleared automatically.

Verify It Yourself

Open your browser's Developer Tools (F12 or Ctrl+Shift+I), switch to the Network tab, and convert any file. You will see zero network POST requests carrying file data.

Status: Waiting for input...
Header: Algorithm & Token Type
 
Payload: Data & Claims
 
Signature
Unverified Signature String

Understanding JSON Web Tokens (JWT)

JSON Web Tokens (JWT) are an open, industry-standard (RFC 7519) method for securely representing claims between two parties. They are widely used in modern web applications for user authentication, session management, and API authorization. A standard JWT consists of three distinct parts separated by dots (.): the Header, the Payload, and the Signature.

1. The Header

The header typically consists of two parts: the type of token (which is JWT) and the cryptographic signing algorithm being used, such as HMAC SHA-256 (HS256) or RSA (RS256). This JSON object is then base64url encoded to form the first part of the token.

2. The Payload

The payload contains claims—statements about an entity (typically, the user) and additional data. Claims are categorized into registered claims (such as iss for issuer, exp for expiration time, sub for subject, and aud for audience), public claims, and private custom claims defined by your application. Like the header, the payload is Base64URL encoded.

3. The Signature

To create the signature part, the encoded header, encoded payload, a secret key, and the algorithm specified in the header are passed through a cryptographic hash function. The signature is used to verify that the sender of the JWT is who it says it is and to ensure that the message was not tampered with along the way.

Why Local Client-Side Decoding Matters

Because JWT payloads frequently contain user IDs, authorization roles, email addresses, and session expiration timestamps, sending your production or staging JWT tokens to external server endpoints poses a privacy risk. FreeFileTool's JWT Decoder runs 100% inside your local browser tab, guaranteeing that your authorization tokens never leave your machine.

Frequently Asked Questions

Is it safe to paste my JWT tokens into this decoder?

Yes, 100%. FreeFileTool decodes JSON Web Tokens entirely inside your browser's local memory using pure JavaScript base64url parsing. Your token is never uploaded or sent across any network.

Does this tool verify the JWT signature?

This tool decodes and displays the unencrypted Header and Payload metadata contained within the JWT. Signature verification requires the private key or secret key which remains on your authentication backend server.

How are JWT timestamps formatted?

Standard JWT claims like exp (expiration), iat (issued at), and nbf (not before) are stored as Unix epoch timestamps (seconds since Jan 1, 1970). Our tool converts these numeric values into readable ISO and local time strings automatically.

What is base64url encoding in JWTs?

JWTs use Base64URL encoding, which is a variant of Base64 that replaces '+' with '-' and '/' with '_' while omitting trailing '=' padding characters to ensure tokens can be safely transmitted in HTTP headers and URL parameters.