Decode and inspect a JSON Web Token (JWT)
A JSON Web Token has three Base64URL parts: header, payload and signature. Paste a token to see the algorithm, the claims and human-readable dates for exp, iat and nbf, and to check whether it has expired.
Decoded locally. Your token is never sent anywhere. Signature is not verified.
JWT Decoder: 3 simple steps
- 1
Paste your JWT into the box.
- 2
Read the header, payload and time claims that appear automatically.
- 3
Check the expiry status before debugging authentication issues.
Tokens are decoded entirely in your browser and are never uploaded, which matters because a JWT is a credential. Note that decoding does not verify the signature.
Built for speed and privacy
- Shows exp, iat and nbf as readable dates
- Flags expired tokens
- Never leaves your browser
- Pretty-printed header and payload
JWT Decoder FAQ
The token is decoded locally and never sent to a server. Still, avoid sharing live production tokens anywhere and rotate a token if you suspect it was exposed.
No. Decoding only reads the header and payload. Verifying a signature requires the secret or public key and should be done in your backend.
exp is when the token expires, iat is when it was issued and nbf is the time before which it must not be accepted. All are Unix timestamps in seconds.
A JWT must have three dot-separated Base64URL parts. Remove any surrounding quotes or the Bearer prefix and try again.
Need secure authentication for your product?
We build auth, roles and secure APIs into SaaS platforms and web apps.