Developer TOOL

JWT Decoder

Split a token into its three parts, decode the header and payload from the URL-safe Base64, and read the expiry as a date. Nothing is verified. Furtu says so on the page, because the contents of a token are whatever the person who made it chose to write, and treating them as proof of identity is the mistake this tool exists to prevent.

Processed locally in your browser — your file is never uploaded

DEVELOPERJWT Decoder
Processed locally
Input
Output

Replaces payload fields named like a password, key or token with their length, so a screenshot of this page is safer to share.

Your text never leaves this page.

How jwt decoder works

  1. Paste the tokenA leading “Bearer ” is stripped for you.
  2. Read the three partsHeader, payload and signature, with the URL-safe Base64 decoded and pretty-printed.
  3. Check the expiryExpiry, issued-at and not-before are shown as readable dates, with how long is left.

What you get

Read a JSON Web Token — and see, clearly, that it proves nothing. Everything happens inside this page: the file is read by your browser, transformed in memory and handed straight back to you as a download. There is no upload queue, no waiting for a server, and nothing left behind when you close the tab.

Supported formats

This tool works on text you paste or type, so there is no file format to worry about. Nothing you type is sent anywhere.

Limitations, stated up front

  • The signature is never verified. Nothing here should be used to make an authentication decision.
  • Encrypted tokens, which have five parts, cannot be read.
  • A revoked token still looks valid: revocation is recorded on the server, not in the token.

Frequently asked questions

Does Furtu verify the signature?

No, and it cannot. Verifying a signature needs the key: the public key for RS256, or the shared secret for HS256. Verifying with the token’s own key would prove nothing, and Furtu has no key material and makes no request. What it does is decode, and that is a completely different operation from verifying.

So why trust anything it shows?

Treat the contents as a claim rather than a fact. A decoded payload is useful for debugging — which scopes were granted, when it expires, what the issuer says — and worthless as proof. The only trustworthy answer to “is this token valid?” comes from the server that issued it, checked against its key.

What does an unsigned algorithm mean?

That the token is not signed. Anyone can write one, and a server that accepts it accepts a token anyone forged. If you are reviewing a system, that line in the header is worth a conversation.

Why can a token have five parts?

That is an encrypted token. Furtu does not decrypt, because decryption needs a key, and a five-part value here means the payload is not visible to anyone without one.

Is my token sent anywhere?

No — and this is the most important property this tool has. A token is a live credential for as long as it is valid, so it is decoded in your browser and never transmitted, stored or logged.