Skip to content
POST /api/v1/decode-jwt

JWT Decoder

Paste a JWT token to decode it. The tool extracts and displays the header (algorithm, type), payload (claims, expiration, subject), and signature. It does not verify the signature — this is a decoding tool for debugging, not a security validator.

string required
X-Sandbox-Remaining: - get an api key

returns

data.payload
The decoded claims, like sub, iat and exp.
data.header
Token header with the algorithm and type.
data.is_expired
True when exp is in the past, only present if exp is set.
data.expires_at
The exp claim as an ISO 8601 date.
data.issued_at
The iat claim as an ISO 8601 date.
data.signature
The raw signature segment, which isn't verified.
response awaiting request sending
Fill in the fields and send a request. The response lands here.

Run it from your code

A temporary key takes one request and lasts seven days at 20 calls a day. Register and it becomes 75 a day, still free.

$ curl -sX POST "https://apixies.io/api/v1/decode-jwt" \
    -H "X-API-Key: $APIXIES_KEY" \
    -H "Content-Type: application/json" \
    -d '{"token":"..."}' | jq '.data.payload'

questions

Is it safe to paste my JWT here?

The decoding happens via an API call. Don't paste production tokens with sensitive claims unless you trust the service. For sensitive tokens, decode them locally using your language's JWT library. JWTs are encoded (base64), not encrypted — anyone with the token can read the payload.

Does this verify the JWT signature?

No. This tool decodes the token to show its contents. Signature verification requires the secret key or public key, which you wouldn't want to share with an online tool.

cookies

We use analytics cookies to see how the site gets used. Nothing loads until you accept. Privacy policy