Developer guides
How to Decode a JWT: Online, JavaScript & Command Line
Updated 25 September 2026 · 4 min read
A JWT is three Base64URL strings joined by dots: header.payload.signature. Decoding means turning the first two back into JSON. (New to JWTs? Start with what a JWT is.)
The quickest way
Paste the token into the JWT decoder. It shows the header and payload, and converts iat, exp and nbf into readable dates — telling you at a glance whether the token has expired. It runs entirely in your browser.
In JavaScript
function decodeJwt(token) {
const [header, payload] = token.split(".").slice(0, 2).map((part) => {
const b64 = part.replace(/-/g, "+").replace(/_/g, "/");
const json = new TextDecoder().decode(Uint8Array.from(atob(b64), (c) => c.charCodeAt(0)));
return JSON.parse(json);
});
return { header, payload };
}Base64URL uses - and _ instead of + and /, and drops the = padding — swap them back before atob. The TextDecoder step keeps names in Hindi or other scripts intact.
In Python
import base64, json
def decode_part(part):
part += "=" * (-len(part) % 4) # restore padding
return json.loads(base64.urlsafe_b64decode(part))
header, payload = (decode_part(p) for p in token.split(".")[:2])On the command line
echo "$TOKEN" | cut -d. -f2 | tr '_-' '/+' | base64 -d 2>/dev/null; echoIf the output is cut short, add one or two = at the end of the middle part — the padding JWTs leave out.
Decoding is not verifying
Anyone can create a token with any payload. Your server must verify the signature (with the HS256 secret, or the RS256/ES256 public key) using a proper library, and check exp, iss and aud, before trusting a single claim. Also reject tokens whose header says "alg": "none".
Frequently asked questions
Is it safe to paste a JWT into an online decoder?
Only if the decoder runs in your browser. EverythingTool's JWT decoder never sends the token anywhere. Avoid pasting live production tokens into sites that upload them.
Does decoding a JWT verify it?
No. Decoding only reads the payload. To trust it, a server must verify the signature with the secret or public key and check exp, iss and aud.
