JWT Decoder

Paste a JSON Web Token to read its header and payload, see what each claim means, and check when it expires. The token is decoded on your device and never sent anywhere.

Decode a JSON Web Token

Header, payload, claims and expiry — decoded locally.

Decoding a JWT does not verify its signature. Anyone can create a token with any content. Only a server with the right key can confirm a token is genuine — never trust a token just because it decodes.
"Bearer " is removed automatically

Decoded token

The header, payload, claims and signature appear here as soon as you paste a token.

How to use it

  1. Paste the token. A leading "Bearer " is removed for you, as are spaces and line breaks.
  2. Read the header (algorithm and key ID) and the payload (the claims) as formatted JSON.
  3. Check "Claims explained" for what standard claims such as iss, sub, aud, exp and iat mean, with times shown in your local time and UTC.
  4. Copy the header or payload JSON if you need it elsewhere.

Good to know

Decoding is not verifying
A JWT's header and payload are only Base64URL-encoded, not encrypted, so anyone can read them. The signature proves who issued the token, and checking it requires the issuer's secret or public key. This tool never says a token is valid.
Is it safe to paste a real token?
The token is processed by JavaScript on this page and is not uploaded, logged or stored. Even so, treat live tokens like passwords: prefer expired or test tokens when you can.
Times are in seconds
exp, iat and nbf are Unix timestamps in seconds. If a value looks like milliseconds, the tool warns you — that is a common bug.

Frequently asked questions

Does this tool verify the JWT signature?

No. It decodes the token so you can read it. Decoding a JWT does not verify its signature, so the contents may have been changed by anyone.

What are the three parts of a JWT?

The header (which algorithm signed it), the payload (the claims, such as user ID and expiry) and the signature. Each part is Base64URL-encoded and they are joined with dots.

Why does it say my token is expired?

The exp claim is earlier than the current time on your device. If your device clock is wrong, the result will be too.

Can it decode encrypted tokens (JWE)?

No. A JWE has five parts and its payload is encrypted, so it can only be read with the decryption key.

Say hello

Let’s connect.

Have an idea, a project, a collaboration — or just want to say hello? I read every message.

Write to me