JWT Decoder
Decode a JWT to see its header, payload and expiry.
This tool only decodes the token and does not verify its signature. Do not treat the result as proof that the token is valid.
Your data is processed entirely in your browser and is never sent to a server.
How to use JWT Decoder
- Paste a JWT (in the form xxxxx.yyyyy.zzzzz) into the JWT box.
- The header and payload are decoded and shown as JSON as soon as you paste.
- The iat, nbf and exp time claims are converted to dates, with a note saying whether the token is still valid or has expired.
Frequently asked questions
Does the tool verify the token signature?
No. It only decodes the header and payload so you can read them. Signature verification must happen on your server with the secret or public key.
Is it safe to paste a real token here?
The token is decoded in your browser and never sent to a server. Even so, avoid pasting live production tokens into any website you do not trust.
Is the JWT payload encrypted?
No. The payload is only Base64URL-encoded, so anyone holding the token can read it. Never put passwords or sensitive data in the payload.
Other tools
View all
Base64 Encode / Decode
Encode and decode Base64 with full UTF-8 support and a URL-safe option.
Unix Timestamp Converter
Convert Unix timestamps to dates and back, in local time and UTC.
Code Formatter
Format, minify and validate JSON, XML, HTML, CSS, JavaScript, SQL and YAML.
Hash Generator
Generate MD5, SHA-1, SHA-256 and SHA-512 hashes from text.