JWT Decoder

Paste a JSON Web Token to inspect its header and payload, check expiry with readable timestamps, and verify structure — entirely on your device.

100% client-side Free forever No sign-up

Runs 100% in your browser — nothing is ever uploaded.

Frequently asked questions

Is it safe to generate passwords in a browser?

Yes — we use the Web Crypto API (crypto.getRandomValues), the same cryptographically secure randomness source used by password managers. Generation happens on your device and nothing is transmitted or stored.

Do you see the JWT tokens I decode?

No. Decoding is pure client-side Base64 parsing — the token never leaves your browser. Still, avoid pasting production secrets anywhere as a general habit.

Are the UUIDs really unique?

UUID v4 has 122 random bits — the collision probability is so small it is negligible for any real-world system. We use the native crypto.randomUUID() implementation.