JWT Offline Decoder
Offline JWT Decoder & Token Inspector
Inspect JWT header algorithms, claims, and expiration timestamps. Runs 100% client-side in your browser for total token privacy.
Local Base64Url decode only; does not verify backend secret signature
JWT 离线解码
JSON Web Token 载荷与过期时间检查
🔒 纯前端解码,Token 和密钥绝不上报至任何服务器,保障生产环境与私密凭据安全。
{
"alg": "HS256",
"typ": "JWT"
}{
"sub": "1234567890",
"name": "Alice Dev",
"admin": true,
"iat": 1516239022,
"exp": 1951623902
}How it works
JWT Structure & Privacy Guidelines
A JSON Web Token consists of three parts: Header, Payload, and Signature, separated by dots. Headers and payloads are Base64Url encoded—not encrypted—making them readable by anyone.
Unlike online services that capture tokens on backend servers, this tool processes everything locally in browser memory. Even sensitive production bearer tokens remain confidential.
JWT = Base64Url(Header) . Base64Url(Payload) . Signature
FAQ
Offline JWT Decoder & Token Inspector · FAQ
Is it safe to paste production tokens here?
Yes, 100%. The decoding logic runs entirely in your local browser window. No network requests are sent with your token.
Why can I read claims without a secret key?
JWT payload is Base64Url encoded for data transport, not encrypted. The signature verifies integrity, not confidentiality.
What do 'exp' and 'iat' stand for?
'exp' is the expiration Unix timestamp; 'iat' is the issued-at Unix timestamp.