JWT Decoder

Paste a JSON Web Token to see what is inside it: the algorithm, the claims and, in plain dates, when it was issued and when it expires.

Decoding happens in this browser tab. Even so, treat live production tokens like passwords.

Runs in your browser. What you enter here is not sent to our server.

  • Header and payload as formatted JSON
  • Expiry shown as a readable date
  • The token stays in your browser

How to use the JWT Decoder

  1. Paste the token. A leading “Bearer ” is ignored.
  2. Read the header and payload, shown as formatted JSON.
  3. Check the dates table to see whether the token has expired.

What a JWT contains

A token has three Base64URL parts separated by dots. The header names the signing algorithm. The payload holds claims such as sub (who the token is about), iat (issued at) and exp (expiry), stored as Unix timestamps. The signature lets a server confirm the first two parts were not altered. The payload is only encoded, not encrypted: anyone holding the token can read it, which is why secrets never belong in a JWT.

Questions about the JWT Decoder

Does this tool verify the signature?

No. Verification needs the secret or public key and belongs on your server. This tool only shows the contents.

Is it safe to paste a token here?

Decoding happens entirely in your browser and the token is not sent anywhere. Even so, prefer test tokens over live production ones as a habit.