JWT Decoder

Read the header and payload of a JSON Web Token.

Developer Tools Free, no sign-up Runs in your browser

JWT Decoder tool

A leading Bearer prefix and any whitespace are ignored.

This tool decodes only. It never verifies the signature, because that would require your signing key, and a signing key should never be pasted into a web page.

About the JWT Decoder

A JSON Web Token is three Base64-encoded sections separated by full stops: a header saying how it was signed, a payload of claims, and a signature. The first two are encoded, not encrypted, which means anyone holding a token can read what is inside it. This tool does exactly that, and shows the result as formatted JSON.

Timestamp claims are the ones people most often need. The decoder converts issued-at, not-before and expiry into readable dates and tells you whether the token has expired and by how long. The standard registered claims are also labelled, so you can see at a glance which value is the subject, the issuer and the audience.

One thing this tool deliberately does not do is verify the signature. Verification requires the secret or public key, and pasting a signing secret into a web page is exactly the habit that leads to leaked credentials. Decoding tells you what a token says; only your server, holding the key, can tell you whether to believe it.

How to use the JWT Decoder

  1. Paste the tokenDrop in the full three-part token. Whitespace and a leading Bearer prefix are ignored.
  2. Read the headerIt shows the signing algorithm and token type.
  3. Read the payloadClaims are shown as formatted JSON, with timestamps converted to dates.
  4. Check the expiryThe status line says whether the token is still valid and when it expires.

Features

  • Decodes the header and payload as formatted JSON
  • Converts issued-at, not-before and expiry into readable dates
  • Says whether the token has expired and by how much
  • Labels the standard registered claims
  • Handles URL-safe Base64 and missing padding
  • Clear errors for tokens with the wrong shape
  • Never transmits the token, and never asks for your signing key

Who uses this tool

The jwt decoder is used by writers, developers, students, marketers and anyone else who needs the job done once without installing software. Common cases include:

  • Checking why an API call is being rejected as unauthorised
  • Confirming which user or scope a token represents
  • Seeing when a token expires while debugging a session problem
  • Inspecting the claims an identity provider actually issues
  • Learning how JSON Web Tokens are structured

Frequently asked questions

Does this verify that the token is genuine?

No, and that is deliberate. Verification needs the signing secret or public key, and pasting a secret into a web page is a bad habit regardless of who runs the page. Decoding shows what a token claims; only a server holding the key can confirm it was really issued.

Is a JWT encrypted?

No. The header and payload are Base64-encoded, which is reversible by anyone. Never put a password, a card number or any other secret in a token payload, because every holder of the token can read it.

What do exp, iat and nbf mean?

Expiry, issued-at and not-before. All three are Unix timestamps in seconds, which is why they look like meaningless numbers until converted. The decoder shows the readable date beside each one.

Why does my token fail to decode?

A JWT has exactly three sections separated by full stops. If a section is missing or a character was lost when copying, decoding stops. Tokens are often truncated when copied out of a log or a terminal window.

Is it safe to paste a real token here?

Decoding happens entirely in your browser and the token is never transmitted. Even so, treat a live token like a password: if it has been shared somewhere you do not control, have it revoked.

Can I see the signature?

The third section is shown as raw text. It is a binary value rendered in URL-safe Base64, so it will not look like anything readable, and it cannot be checked without the key.

If the jwt decoder is not quite what you need, these other free tools solve closely related problems.

Base64 Decoder

Decode Base64 back to text, with friendly errors for malformed input.

Encoding & Conversion Use tool

JSON Formatter

Pretty-print and validate JSON, with the exact line and column of any error.

Developer Tools Use tool

Hash Generator

Generate cryptographic hashes of text, computed in your browser.

Developer Tools Use tool

Timestamp Converter

Translate between Unix time and human-readable dates in both directions.

Developer Tools Use tool

URL Decoder

Decode %20 and other percent escapes back into normal characters.

Encoding & Conversion Use tool