JWT Decoder

Decode a JWT's header and payload and see exp, iat and nbf as readable dates.

Runs in your browser Free
This tool decodes the token but does not verify its signature. The token never leaves your browser.

What is a JWT?

A JSON Web Token (JWT) is a token made of three dot-separated parts widely used for authentication and authorisation: header, payload and signature. The first two parts are Base64URL-encoded JSON and are easy to decode.

What the decoder shows

  • The header with algorithm and token type
  • The payload with user ID, roles and custom claims
  • Readable dates for exp (expiry), iat (issued at) and nbf (not before)
  • Whether the token has expired

Security note

Decoding happens in your browser and the token is never sent anywhere. Still, avoid pasting valid production tokens on shared computers.

How to use JWT Decoder

  1. Paste the JWT.
  2. The header and payload are decoded automatically.
  3. Review the time claims and expiry status.
  4. Copy the JSON content if needed.

Why use this tool?

See a token's content instantly while debugging authentication; the token never leaves your device.

FAQ

Does it verify the signature?

No. It only decodes the token. The token doesn't leave your browser, but avoid pasting live production secrets.

Is the JWT content secret?

No. The payload is encoded, not encrypted, so never put sensitive data such as passwords in a JWT.

Why does my token show as expired?

The time in the exp claim is in the past. You need a new token.

Related tools