JWT Offline Decoder

Offline JWT Decoder & Token Inspector

Inspect JWT header algorithms, claims, and expiration timestamps. Runs 100% client-side in your browser for total token privacy.

Local Base64Url decode only; does not verify backend secret signature

JWT 离线解码

JSON Web Token 载荷与过期时间检查

🔒 纯前端解码,Token 和密钥绝不上报至任何服务器,保障生产环境与私密凭据安全。

过期时间 (exp): 11/5/2031, 1:45:02 PM (有效)
签发时间 (iat): 1/18/2018, 9:30:22 AM
HEADER(头部算法与类型)
{
  "alg": "HS256",
  "typ": "JWT"
}
PAYLOAD(载荷声明与字段)
{
  "sub": "1234567890",
  "name": "Alice Dev",
  "admin": true,
  "iat": 1516239022,
  "exp": 1951623902
}

How it works

JWT Structure & Privacy Guidelines

A JSON Web Token consists of three parts: Header, Payload, and Signature, separated by dots. Headers and payloads are Base64Url encoded—not encrypted—making them readable by anyone.

Unlike online services that capture tokens on backend servers, this tool processes everything locally in browser memory. Even sensitive production bearer tokens remain confidential.

JWT = Base64Url(Header) . Base64Url(Payload) . Signature

FAQ

Offline JWT Decoder & Token Inspector · FAQ

Is it safe to paste production tokens here?

Yes, 100%. The decoding logic runs entirely in your local browser window. No network requests are sent with your token.

Why can I read claims without a secret key?

JWT payload is Base64Url encoded for data transport, not encrypted. The signature verifies integrity, not confidentiality.

What do 'exp' and 'iat' stand for?

'exp' is the expiration Unix timestamp; 'iat' is the issued-at Unix timestamp.