/

JWT Decoder

Processed Client Side

Decode and inspect JSON Web Token header, payload, and signature. Timestamps are shown in human-readable form.

Token · 1 line
3 parts
Length: 197Lines: 1Size: 197 BytesCursor: 1:1
Decoded
Valid JWTHS256Expired
HEADER
4 lines
{
  "alg": "HS256",
  "typ": "JWT"
}
PAYLOAD
7 lines
{
  "sub": "1234567890",
  "name": "Jane Doe",
  "iat": 1716239022,
  "exp": 1716242622,
  "role": "admin"
}
iat5/20/2024, 9:03:42 PM
exp5/20/2024, 10:03:42 PM
sub1234567890
SIGNATURE
Not verified (no secret)
1SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c

Bookmark this tool now — skip the search next time you need it.

About JWT Decoder

This tool runs entirely in your browser. Whatever you paste is processed on your own device and is never uploaded, logged, or sent to any server.

Paste a JSON Web Token and immediately see what is inside it. A JWT is three Base64url segments separated by dots — a header describing the signing algorithm, a payload holding the claims, and a signature. This decoder splits the token, decodes the first two segments into readable JSON, and shows the signature separately without attempting to verify it. Standard time claims are translated from raw epoch numbers into human dates, and the token is checked against the current time so an expired token is flagged as expired rather than leaving you to do the arithmetic. It is the quickest way to answer "what user is this token for, what scopes does it carry, and has it already expired".

Key features

  • Splits and decodes the header and payload of any JWT into formatted, colour-highlighted JSON
  • Expiry check against the current time, with clear Expired or Active status
  • Human-readable dates for the standard exp, iat, and nbf time claims instead of raw epoch seconds
  • Header section shows the signing algorithm and token type, which is where you confirm the algorithm is what you expect
  • Signature segment is displayed as-is and clearly marked as not verified
  • Handles base64url encoding and missing padding, which is what breaks a generic Base64 decoder on JWTs
  • Clear errors for tokens with the wrong number of segments or an undecodable payload
  • Copy the decoded payload as JSON in one click
  • Runs entirely in your browser — access tokens are never transmitted anywhere

How to use it

  1. Paste the full token — all three dot-separated segments — into the input pane.
  2. Click Decode.
  3. Read the header to see the algorithm, and the payload for the claims.
  4. Check the status badge for Expired or Active, and read the formatted exp and iat dates.
  5. Click Copy payload if you need the claims as JSON elsewhere.

Tips & common mistakes

  • Decoding is not verification. Anyone can read a JWT and anyone can forge one that decodes cleanly — only checking the signature against the secret or public key on your server proves it is genuine.
  • Because the payload is readable by anyone holding the token, never put passwords, card numbers, or anything private in it. Base64url is transport encoding, not protection.
  • If the header says alg is none, treat the token as hostile. Accepting an unsigned token is a well-known authentication bypass.
  • exp and iat are seconds since the epoch, while JavaScript Date works in milliseconds. Comparing them without multiplying by 1000 is the single most common JWT bug.
  • A token that looks valid but is rejected by your API is often a clock problem — nbf and exp are evaluated against server time, so a few minutes of drift between machines will reject a fresh token.
  • Three segments means a signed JWS, which is what this tool reads. A token with five segments is an encrypted JWE and its payload cannot be decoded without the key.
  • To create a token from scratch rather than decode an existing one, use the JWT Builder.

Related tools

Browse all 4 Encoding tools

Frequently asked questions

10

Paste your JWT (the three dot-separated parts) into the input and the header, payload, and signature are decoded and displayed instantly.

No — signature verification requires the secret or public key, which you should never share with a third-party tool. This tool decodes and displays the payload only.

All decoding happens entirely in your browser — the token is never sent to any server. That said, avoid pasting production tokens with sensitive claims into any online tool.

iat = "issued at" (when the token was created), exp = "expiration time" (when it becomes invalid), nbf = "not before" (earliest valid time). All three are shown as human-readable dates.

The exp claim contains a Unix timestamp in the past, meaning the token is no longer valid for authentication. You need to request a new token from your auth server.

Decoding only reads the token; it does not check the signature or the clock. A token that reads correctly can still be rejected for a bad signature, or because nbf and exp are evaluated against server time and the two machines have drifted apart.

Treat the token as hostile. An unsigned token that a server accepts is a well-known authentication bypass, and no production system should accept alg none.

The exp claim is in seconds since the epoch, while JavaScript Date works in milliseconds. Comparing them without multiplying by 1000 is the most common JWT bug there is.

No. The payload is Base64url encoded, not encrypted, so anyone holding the token can read every claim. Signing proves the token was not altered; it does nothing to hide the contents.

Check the segment count. A signed JWT has three dot-separated segments, which is what this tool reads. Five segments means an encrypted JWE, whose payload cannot be decoded without the key.