개발자 도구

JWT 디코더

JSON Web Token 디코딩 및 검사 — 헤더, 페이로드 및 서명 확인

This tool decodes JWT tokens client-side without verification. Never share production tokens with any online tool.
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c

Header

{
  "alg": "HS256",
  "typ": "JWT"
}

Signature

SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c

Signature is not verified

Payload

{
  "sub": "1234567890",
  "name": "John Doe",
  "iat": 1516239022
}

Issued: 1/18/2018, 1:30:22 AM

JWT Decoder & Inspector

Decode and inspect JSON Web Tokens (JWT) instantly. Paste a JWT to see the decoded header, payload, and expiration — without needing the secret key. Useful for debugging auth flows.

FAQ

What is a JWT?

A JWT (JSON Web Token) is a compact, URL-safe token format used for authentication. It contains three Base64url-encoded parts: header, payload, and signature.

Can I verify a JWT without the secret?

You can decode the header and payload without the secret. To verify the signature (confirm it hasn't been tampered with), you need the signing key.

Is it safe to paste my JWT here?

This tool decodes entirely in your browser — nothing is transmitted to a server. However, never share JWTs publicly as they grant access to whatever they authorize.

What does 'exp' mean in a JWT payload?

'exp' is the expiration time as a Unix timestamp. If the current time is past exp, the token is expired and should be rejected.

필요한 게 없나요?

커뮤니티 피드백으로 무료 도구를 만듭니다. 워크플로에 필요한 도구를 제안해 주세요!

JWT 디코더 — 무료 도구 온라인 | FreeTool24 | FreeTool24