AnkhKit

JWT Decoder & Parser Online — Free

Runs 100% in your browser — your files never leave your device.

A JSON Web Token is readable even when it is signed, but manually splitting and base64url-decoding the sections is tedious. Paste a three-part JWT to inspect its header, claims, and signature segment. This parser deliberately does not claim to verify authenticity.

How it works

  1. 1

    Paste the JWT

  2. 2

    Inspect header and claims

  3. 3

    Treat decoded data as unverified

About this tool

What decoding shows

A JWT is three base64url parts joined by dots: header, payload, signature. The tool decodes the first two and displays the claims — issuer, expiry, subject, and everything custom. The signature is data, not something you decode; it exists to be verified with a key.

Debugging with the payload

Expired tokens, wrong audiences, and missing roles explain most 401s. Decode the failing token and read the claims directly: exp versus the server clock, aud versus the expected value, the actual scopes granted. The answer is usually sitting right in the payload.

Two cautions

Decoding is not verification — this tool shows the claims without checking the signature, so never trust a decoded token's content in an application without verifying it server-side. And tokens carry real session data: do not paste production tokens anywhere you would not paste the user's personal information.

Frequently asked questions

Can the tool validate my token's signature?

No — signature verification needs the signing key or public key and happens in your server or auth library. This tool decodes and displays; that is the debugging half.

Why does my token show "Invalid date" for exp?

The exp claim is a Unix timestamp in seconds. If the payload holds something else — milliseconds or a string — the date display misreads it. The raw value is shown so you can convert manually.

Is pasting a JWT here safe?

Decoding runs entirely in your browser and nothing is sent anywhere. Still, treat tokens as sensitive: decode test tokens when you can, and never rely on an unverified decode for access decisions.

More developer tools