JWT Decoder
Decode a JWT's header and payload and see exp, iat and nbf as readable dates.
What is a JWT?
A JSON Web Token (JWT) is a token made of three dot-separated parts widely used for authentication and authorisation: header, payload and signature. The first two parts are Base64URL-encoded JSON and are easy to decode.
What the decoder shows
- The header with algorithm and token type
- The payload with user ID, roles and custom claims
- Readable dates for exp (expiry), iat (issued at) and nbf (not before)
- Whether the token has expired
Security note
Decoding happens in your browser and the token is never sent anywhere. Still, avoid pasting valid production tokens on shared computers.
How to use JWT Decoder
- Paste the JWT.
- The header and payload are decoded automatically.
- Review the time claims and expiry status.
- Copy the JSON content if needed.
Why use this tool?
See a token's content instantly while debugging authentication; the token never leaves your device.
FAQ
Does it verify the signature?
No. It only decodes the token. The token doesn't leave your browser, but avoid pasting live production secrets.
Is the JWT content secret?
No. The payload is encoded, not encrypted, so never put sensitive data such as passwords in a JWT.
Why does my token show as expired?
The time in the exp claim is in the past. You need a new token.
Related tools
Base64 Encoder / Decoder
Encode text to Base64 and decode it back with full UTF-8 support, including URL-safe Base64.
Open toolJSON Formatter and Validator
Pretty-print messy or minified JSON and find errors with line and column details.
Open toolUnix Timestamp Converter
Convert Unix timestamps to dates and dates to timestamps, in seconds or milliseconds.
Open toolHash Generator (MD5, SHA-256)
Calculate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes of text or files.
Open tool