Paste your JWT token

About this tool

This JWT decoder splits a JSON Web Token into its header, payload and signature, base64url-decodes them into readable JSON and shows the algorithm, issued-at time and expiry status.

How to use it

  1. Paste the token into the input box.
  2. Click Decode.
  3. Read the algorithm, type, issue time and expiry banner, then inspect the header and payload JSON.
  4. Copy the header or payload if you need it.

Good to know

  • A JWT (RFC 7519) has three base64url-encoded parts separated by dots: header.payload.signature.
  • The exp and iat claims are Unix timestamps in seconds; the tool converts them to local dates and shows how long until or since expiry.
  • Decoding does not verify the signature — anyone can read a JWT's contents, so never put secrets in the payload.
  • The alg header names the signing algorithm, such as HS256 or RS256.

Runs entirely in your browser — nothing you enter is uploaded or stored.

Frequently asked questions

Does this tool verify the JWT signature?

No. It only decodes the token. Signature verification requires the secret or public key and should be done on your server.

Is it safe to paste a production token here?

The token is decoded in your browser and never sent to a server. Still, treat live tokens like passwords and avoid sharing them.

Why does my token say it is expired?

The exp claim is earlier than your device's current time. Check that your clock is correct and that the token was issued recently.

Are JWTs encrypted?

Standard signed JWTs (JWS) are only encoded, not encrypted, so their contents are readable by anyone who has the token.