JWT Token Decoder & Claims Viewer

Paste a JWT to inspect its header claims, payload data, and expiration status.

—


Embed this tool on your website / blog No code required · Copy and paste
HTML Embed Code (iframe):
<iframe src="https://lucentool.com/jwt-decoder" width="100%" height="650" style="border:1px solid #e5e0d8;border-radius:12px;max-width:850px;width:100%;" frameborder="0"></iframe>
<div style="font-size:12px;color:#78716c;margin-top:6px;font-family:sans-serif;">Powered by <a href="https://lucentool.com/jwt-decoder" target="_blank" style="color:#c85a32;text-decoration:none;">Lucentool - JWT Token Decoder & Claims Viewer</a></div>

Anatomy of a JWT

A JWT is three base64url segments separated by dots: header.payload.signature. The header declares the algorithm (alg) and type; the payload carries claims like sub (subject), iat (issued at), and exp (expiry); iat and exp are Unix timestamps. The signature proves the token wasn't tampered with.

Reading the decode

Security note

JWTs are base64, not encrypted — anyone can read the payload. Never put secrets in them, and never paste tokens containing sensitive claims into online tools. This one runs entirely in your browser.