Paste a JSON Web Token to read its header and claims and check when it expires.
| Claim | Value | Meaning |
|---|
Bearer prefix copied from an HTTP header.A JSON Web Token (RFC 7519) is three pieces of text joined by dots: a header, a payload and a signature. The header and payload are JSON objects encoded with URL-safe Base64 without padding (RFC 4648 §5). Decoding them needs no key at all, which surprises many people: anyone holding a token can read what it says. Only the signature is protected, and it proves the token was issued by someone holding the secret or private key.
This tool decodes both JSON parts as UTF-8, pretty-prints them and explains the registered claims. Time claims are NumericDate values, meaning seconds since 1970 UTC: exp is when the token stops being valid, nbf is when it starts, and iat is when it was issued. For example, "exp": 1767225600 is January 1, 2026 at 00:00 UTC; at any later moment the tool marks the token as expired. The status updates every second while the page is open.
What it deliberately does not do is verify the signature. Verifying needs the issuer's secret or public key and should happen in your own server code. So "within its time window" only means the dates allow it; it does not mean the token is genuine. A token with "alg": "none" has no signature at all, and the tool flags it. Encrypted tokens (JWE, five parts) can only show their header here, because the payload needs the decryption key.
Is it safe to paste my token here?
The decoding runs entirely in your browser; the token is not sent, logged or stored, and nothing is saved when you leave the page. Still, a live token works like a password until it expires, so avoid sharing it and prefer test or expired tokens when you can.
Why can anyone read my JWT's payload?
Signed JWTs are encoded, not encrypted. Base64URL is just a way to write bytes as text. Never put secrets such as passwords in a JWT payload unless the token is encrypted (JWE).
Why does it say the token is in its time window but my API rejects it?
The tool only checks the times. Your API also checks the signature, the issuer (iss), the audience (aud) and possibly whether the token was revoked. Clock differences between servers can also matter by a few seconds.
What do exp, iat and nbf mean?exp (expiration time) is when the token stops being accepted, iat (issued at) is when it was created, and nbf (not before) is the earliest time it may be used. All three are seconds since January 1, 1970 UTC.
Can this tool verify or create signatures?
No. It is a reader only. Signature checks belong in your application code, using a maintained JWT library and the correct key.