JWT Decoder
Paste a JSON Web Token to read its header and payload, see what each claim means, and check when it expires. The token is decoded on your device and never sent anywhere.
Decode a JSON Web Token
Header, payload, claims and expiry — decoded locally.
Decoded token
The header, payload, claims and signature appear here as soon as you paste a token.
Header
Payload
Claims explained
Signature
Not verified. To check it, the server recomputes the signature with its secret or public key.
How to use it
- Paste the token. A leading "Bearer " is removed for you, as are spaces and line breaks.
- Read the header (algorithm and key ID) and the payload (the claims) as formatted JSON.
- Check "Claims explained" for what standard claims such as iss, sub, aud, exp and iat mean, with times shown in your local time and UTC.
- Copy the header or payload JSON if you need it elsewhere.
Good to know
- Decoding is not verifying
- A JWT's header and payload are only Base64URL-encoded, not encrypted, so anyone can read them. The signature proves who issued the token, and checking it requires the issuer's secret or public key. This tool never says a token is valid.
- Is it safe to paste a real token?
- The token is processed by JavaScript on this page and is not uploaded, logged or stored. Even so, treat live tokens like passwords: prefer expired or test tokens when you can.
- Times are in seconds
- exp, iat and nbf are Unix timestamps in seconds. If a value looks like milliseconds, the tool warns you — that is a common bug.
Frequently asked questions
Does this tool verify the JWT signature?
No. It decodes the token so you can read it. Decoding a JWT does not verify its signature, so the contents may have been changed by anyone.
What are the three parts of a JWT?
The header (which algorithm signed it), the payload (the claims, such as user ID and expiry) and the signature. Each part is Base64URL-encoded and they are joined with dots.
Why does it say my token is expired?
The exp claim is earlier than the current time on your device. If your device clock is wrong, the result will be too.
Can it decode encrypted tokens (JWE)?
No. A JWE has five parts and its payload is encrypted, so it can only be read with the decryption key.