What is the JWT Decoder?
Paste a JWT to read its header and payload as formatted JSON, plus a human-readable expiry. Decoding happens locally; your token never leaves the page (this tool does not verify signatures).
The tool is part of the Calabi free tools hub — a collection of 99+ browser-based utilities for developers, designers, and content creators. Everything runs client-side: your files and data never leave your device.
How to use the JWT Decoder
- Step 1: Paste the full token (three dot-separated parts).
- Step 2: Read the decoded header and payload.
- Step 3: Check the expiry field if present.
The tool updates in real time as you interact with it. No button-clicking required for most tools — results appear instantly.
Example
eyJ…header.eyJ…payload.signature → { header, payload, expiresAt }
Privacy & security
The JWT Decoder is designed with privacy as a hard constraint, not an afterthought:
- No upload: Your data is processed in your browser's JavaScript engine. No HTTP request is made to any server while you use the tool.
- No account required: The tool works instantly — no email, no sign-up, no cookie consent wall.
- No logging: Calabi does not log what you paste, upload, or generate. The server only delivers the HTML/JS page — it never sees your content.
- Open to inspection: Open your browser's network inspector while using the tool. You'll see zero outbound requests related to your data.
This architecture is particularly important for the Developer category of tools, where the inputs often contain sensitive or proprietary information.
Frequently asked questions
Is the JWT Decoder free?
Yes, completely free with no sign-up. Runs in your browser.
Is it safe to paste sensitive data?
Yes. The JWT Decoder runs entirely client-side in your browser. Nothing is sent to a server. You can verify this with your browser's network inspector — you'll see zero outbound requests when you use the tool.
Does it work offline?
Once the page is loaded, yes. The tool logic is a self-contained JavaScript bundle with no runtime API calls.
What browsers are supported?
Any modern browser — Chrome, Firefox, Safari, Edge. Internet Explorer is not supported.
About Developer utilities
The JWT Decoder is part of the Developer utilities category in the Calabi tools hub. Decode a JSON Web Token's header and payload in your browser. The token is never sent anywhere — safe for inspecting tokens. All tools in this category run entirely in your browser with no server involvement.