Decoding happens in your browser. Your token is never uploaded or stored.
Decode and inspect JSON Web Tokens: header, payload, signature and expiration
Decoding happens in your browser. Your token is never uploaded or stored.
Paste the JWT in the box, or click the wand icon to load an example. A "Bearer " prefix and line breaks are removed automatically.
The header shows the algorithm (alg) and type (typ); the payload shows the claims such as sub, iss, aud and any custom data, pretty-printed as JSON.
The exp, iat and nbf claims are converted into readable dates, and a badge tells you if the token is valid, expired or not valid yet.
For HS256, HS384 and HS512 tokens, type the secret and click Verify to see if the signature matches. Copy any part with its Copy button.
A JSON Web Token is three Base64URL strings joined by dots. The header says how the token was signed, the payload carries the claims, and the signature lets a server check that nobody changed the first two parts.
The decoder shows each part in its own color so you can tell them apart: the header in red, the payload in purple and the signature in blue.
Anyone who has a JWT can read its contents, because Base64URL is an encoding and not encryption. Never put passwords or secrets in a payload. What protects a token is the signature, which only the holder of the secret or private key can produce.
This tool can check HMAC signatures (HS256, HS384, HS512) when you type the secret. RS256, ES256 and other public-key algorithms are decoded but not verified here.
The badge compares exp and nbf with the current time of your device. If your clock is wrong the result will be wrong too. Servers usually allow a few seconds of tolerance, which this tool does not apply.
A token without exp never expires according to its claims, so the badge shows "No expiration".
The token is decoded in your browser with plain JavaScript and the Web Crypto API. It is never sent to a server or saved, so it is safe to inspect real tokens. Still, treat live tokens as passwords and avoid sharing them.
Paste the token in the box. The header, payload and signature appear right away. No button is needed.
Yes. Decoding runs entirely in your browser and the token is never uploaded or stored. Even so, avoid sharing production tokens with anyone.
Because the exp claim is earlier than the current time on your device. Request a new token from the service that issued it.
Yes, for HS256, HS384 and HS512: type the secret and click Verify. Tokens signed with RS256 or ES256 are decoded but not verified.
Yes. The "Bearer " prefix, quotes and extra spaces or line breaks are removed before decoding.
The token has no signature, so nothing proves who created it. Servers should reject such tokens.
Yes. It is free, needs no sign-up and has no limits.