Advertisement
Advertisement

JWT Decoder

Paste a JSON Web Token to read its header and claims and check when it expires.

🔒 Tokens are decoded by your own browser. They are never sent, logged or saved anywhere.

Header


      

Payload


      

Claims explained

ClaimValueMeaning

Signature

Decode only. This tool reads a token's header and payload; it does not check the signature, so it can't tell you whether a token is genuine. Avoid pasting live production tokens into any website you do not trust.

How to use the JWT Decoder

  1. Paste a token into the box. It can include the Bearer prefix copied from an HTTP header.
  2. The token is split into its three colored parts: header, payload and signature.
  3. Check the status line: it says whether the token has expired, is not valid yet, or is currently within its time window.
  4. Read the header and payload as formatted JSON, and the claims table for what each standard field means, with times shown as dates.
  5. Use Copy to grab the decoded JSON. Clear the box when you're done.

How it works

A JSON Web Token (RFC 7519) is three pieces of text joined by dots: a header, a payload and a signature. The header and payload are JSON objects encoded with URL-safe Base64 without padding (RFC 4648 §5). Decoding them needs no key at all, which surprises many people: anyone holding a token can read what it says. Only the signature is protected, and it proves the token was issued by someone holding the secret or private key.

This tool decodes both JSON parts as UTF-8, pretty-prints them and explains the registered claims. Time claims are NumericDate values, meaning seconds since 1970 UTC: exp is when the token stops being valid, nbf is when it starts, and iat is when it was issued. For example, "exp": 1767225600 is January 1, 2026 at 00:00 UTC; at any later moment the tool marks the token as expired. The status updates every second while the page is open.

What it deliberately does not do is verify the signature. Verifying needs the issuer's secret or public key and should happen in your own server code. So "within its time window" only means the dates allow it; it does not mean the token is genuine. A token with "alg": "none" has no signature at all, and the tool flags it. Encrypted tokens (JWE, five parts) can only show their header here, because the payload needs the decryption key.

Frequently asked questions

Is it safe to paste my token here?
The decoding runs entirely in your browser; the token is not sent, logged or stored, and nothing is saved when you leave the page. Still, a live token works like a password until it expires, so avoid sharing it and prefer test or expired tokens when you can.

Why can anyone read my JWT's payload?
Signed JWTs are encoded, not encrypted. Base64URL is just a way to write bytes as text. Never put secrets such as passwords in a JWT payload unless the token is encrypted (JWE).

Why does it say the token is in its time window but my API rejects it?
The tool only checks the times. Your API also checks the signature, the issuer (iss), the audience (aud) and possibly whether the token was revoked. Clock differences between servers can also matter by a few seconds.

What do exp, iat and nbf mean?
exp (expiration time) is when the token stops being accepted, iat (issued at) is when it was created, and nbf (not before) is the earliest time it may be used. All three are seconds since January 1, 1970 UTC.

Can this tool verify or create signatures?
No. It is a reader only. Signature checks belong in your application code, using a maintained JWT library and the correct key.

Advertisement

You might also need