JWT Decoder & Inspector

Decode JWT headers and claims locally without pretending to verify the token.

100% Local Processing

About the JWT Decoder & Inspector

Inspect the structure of a compact JSON Web Token in your browser. The tool decodes the Base64URL-encoded header and payload, displays the signature segment, and summarises common claims such as issuer, audience, issued-at, not-before, and expiration times. It is intentionally a decoder and inspector only: decoding does not verify the signature, issuer, audience, key, or trust relationship, and the token is never sent to VoltUtils.

How to inspect a JWT

  1. Paste the compact token into the input without changing its dots or characters.
  2. Review the decoded header and payload as plain JSON.
  3. Check alg, iss, aud, exp, iat, and nbf in the summaries and time section.
  4. Treat every decoded claim as untrusted until the consuming application independently verifies the token.

Examples and worked results

Three-part structure

Input
xxxxx.yyyyy.zzzzz
Result
Header · Payload · Signature

The first two parts are Base64URL-encoded JSON in a normal JWT/JWS; the final part is displayed but not verified.

Educational payload

Input
{ "sub": "1234567890", "role": "viewer", "exp": 1735689600 }
Result
Readable claims and an expiration timestamp

This is an example only, not a credential.

How JWTs are arranged

A compact signed token is commonly represented as Base64URL(header) + "." + Base64URL(payload) + "." + signature. Base64URL is an encoding, not encryption, which is why a header and payload can be inspected without a secret. Signature verification and claim validation must happen in the application that receives the token.

Common use cases

  • Debugging OAuth or OpenID Connect integrations
  • Inspecting exp, iat, and nbf during development
  • Checking what an API or identity provider returned before server-side validation
  • Learning how JWT headers and registered claims are represented

Important notes and limitations

  • This tool does not verify a signature, issuer, audience, key, or trust relationship.
  • Decoded claims are untrusted until independently validated.
  • Not every OAuth access token is a JWT, and tokens may contain sensitive identifiers.

Practical tips

  • Do not paste production tokens into random websites; VoltUtils keeps this inspection local.
  • Pay particular attention to alg, iss, aud, and exp.
  • Use the consuming application or an established security library for actual verification.

Frequently Asked Questions

What is a JWT?

A compact JSON Web Token commonly has three dot-separated parts: a Base64URL-encoded header, a Base64URL-encoded payload, and a signature segment.

Can a JWT payload be decoded without a secret?

Yes. The header and payload are encoded, not encrypted, so they can be read without the signing key.

Does decoding prove that a JWT is valid?

No. Successful decoding says only that the structure and JSON could be read. It does not prove authenticity or trust.

Does this tool verify the JWT signature?

No. It does not verify signatures, issuers, audiences, keys, or any external trust relationship.

What do exp, iat, and nbf mean?

exp is the expiration time, iat is the issued-at time, and nbf is the not-before time. JWT NumericDate values are normally Unix timestamps in seconds.

Is a JWT encrypted?

Usually not. Ordinary signed JWT/JWS payloads are readable. JWE is a separate encrypted-token standard.

Does VoltUtils upload my token?

No. The token is decoded locally in your browser and is not persisted in storage, cookies, or the URL.