JWT Decoder

Decode and inspect JSON Web Tokens: header, payload, signature and expiration

Decoding happens in your browser. Your token is never uploaded or stored.

How to decode a JWT online

  1. 1

    Paste your token

    Paste the JWT in the box, or click the wand icon to load an example. A "Bearer " prefix and line breaks are removed automatically.

  2. 2

    Read the header and payload

    The header shows the algorithm (alg) and type (typ); the payload shows the claims such as sub, iss, aud and any custom data, pretty-printed as JSON.

  3. 3

    Check the dates and status

    The exp, iat and nbf claims are converted into readable dates, and a badge tells you if the token is valid, expired or not valid yet.

  4. 4

    Verify the signature (optional)

    For HS256, HS384 and HS512 tokens, type the secret and click Verify to see if the signature matches. Copy any part with its Copy button.

What is inside a JWT

A JSON Web Token is three Base64URL strings joined by dots. The header says how the token was signed, the payload carries the claims, and the signature lets a server check that nobody changed the first two parts.

The decoder shows each part in its own color so you can tell them apart: the header in red, the payload in purple and the signature in blue.

  • iss: who issued the token
  • sub: the subject, usually a user id
  • aud: the audience the token is meant for
  • exp: expiration time, in seconds since 1970
  • nbf: the token is not valid before this time
  • iat: when the token was issued

Decoding is not verifying

Anyone who has a JWT can read its contents, because Base64URL is an encoding and not encryption. Never put passwords or secrets in a payload. What protects a token is the signature, which only the holder of the secret or private key can produce.

This tool can check HMAC signatures (HS256, HS384, HS512) when you type the secret. RS256, ES256 and other public-key algorithms are decoded but not verified here.

Expired, valid or not valid yet

The badge compares exp and nbf with the current time of your device. If your clock is wrong the result will be wrong too. Servers usually allow a few seconds of tolerance, which this tool does not apply.

A token without exp never expires according to its claims, so the badge shows "No expiration".

Private by design

The token is decoded in your browser with plain JavaScript and the Web Crypto API. It is never sent to a server or saved, so it is safe to inspect real tokens. Still, treat live tokens as passwords and avoid sharing them.

JWT decoder FAQ

How do I decode a JWT?

Paste the token in the box. The header, payload and signature appear right away. No button is needed.

Is it safe to paste my token here?

Yes. Decoding runs entirely in your browser and the token is never uploaded or stored. Even so, avoid sharing production tokens with anyone.

Why does the tool say the token is expired?

Because the exp claim is earlier than the current time on your device. Request a new token from the service that issued it.

Can it verify the signature?

Yes, for HS256, HS384 and HS512: type the secret and click Verify. Tokens signed with RS256 or ES256 are decoded but not verified.

Does it work with a "Bearer " prefix?

Yes. The "Bearer " prefix, quotes and extra spaces or line breaks are removed before decoding.

What does alg "none" mean?

The token has no signature, so nothing proves who created it. Servers should reject such tokens.

Is it free?

Yes. It is free, needs no sign-up and has no limits.