Skip to content
EverythingTool logo

Developer guides

How to Decode a JWT: Online, JavaScript & Command Line

Updated 25 September 2026 · 4 min read

A JWT is three Base64URL strings joined by dots: header.payload.signature. Decoding means turning the first two back into JSON. (New to JWTs? Start with what a JWT is.)

The quickest way

Paste the token into the JWT decoder. It shows the header and payload, and converts iat, exp and nbf into readable dates — telling you at a glance whether the token has expired. It runs entirely in your browser.

Open the JWT DecoderDecode JSON Web Tokens to inspect header, payload and expiry. Nothing leaves your browser.

In JavaScript

function decodeJwt(token) {
  const [header, payload] = token.split(".").slice(0, 2).map((part) => {
    const b64 = part.replace(/-/g, "+").replace(/_/g, "/");
    const json = new TextDecoder().decode(Uint8Array.from(atob(b64), (c) => c.charCodeAt(0)));
    return JSON.parse(json);
  });
  return { header, payload };
}

Base64URL uses - and _ instead of + and /, and drops the = padding — swap them back before atob. The TextDecoder step keeps names in Hindi or other scripts intact.

In Python

import base64, json

def decode_part(part):
    part += "=" * (-len(part) % 4)          # restore padding
    return json.loads(base64.urlsafe_b64decode(part))

header, payload = (decode_part(p) for p in token.split(".")[:2])

On the command line

echo "$TOKEN" | cut -d. -f2 | tr '_-' '/+' | base64 -d 2>/dev/null; echo

If the output is cut short, add one or two = at the end of the middle part — the padding JWTs leave out.

Decoding is not verifying

Anyone can create a token with any payload. Your server must verify the signature (with the HS256 secret, or the RS256/ES256 public key) using a proper library, and check exp, iss and aud, before trusting a single claim. Also reject tokens whose header says "alg": "none".

Frequently asked questions

Is it safe to paste a JWT into an online decoder?

Only if the decoder runs in your browser. EverythingTool's JWT decoder never sends the token anywhere. Avoid pasting live production tokens into sites that upload them.

Does decoding a JWT verify it?

No. Decoding only reads the payload. To trust it, a server must verify the signature with the secret or public key and check exp, iss and aud.

Open the JWT DecoderDecode JSON Web Tokens to inspect header, payload and expiry. Nothing leaves your browser.
Share this guide WhatsApp X Facebook

Official websites, opening in a new tab. EverythingTool isn't affiliated with them.