JWT Decoder
Decode a JSON Web Token's header and payload and see exp, iat and nbf as dates. Decoding is not verification: the signature is not checked.
Processed locally in your browser. Your text is not uploaded.
What this tool does
Paste a JSON Web Token and read what is inside. The tool splits it into header, payload and signature, decodes the Base64url parts as UTF-8, and pretty-prints the JSON with syntax highlighting. The registered time claims exp (expiry), nbf (not before) and iat (issued at) are shown as readable dates with a clear expired, not-yet-valid or valid-now indicator relative to your device's clock.
Important: decoding is not verification. A JWT's header and payload are only encoded, not encrypted, and anyone can create a token with any content. This tool never checks the signature, the issuer, the audience or any other claim, so a token that decodes here may still be forged, tampered with or revoked. Never trust a token merely because it decodes. Verification must be done by your server with the correct key.
Tokens are credentials. Decoding happens entirely in your browser and the token is never sent anywhere, but you should still avoid pasting live production tokens on devices you do not control. The tool also warns when a token claims alg “none” or has no signature, which are classic signs of an unsafe or forged token.
How to use it
- 1Paste the full token (three parts separated by dots). A leading “Bearer ” is removed for you.
- 2Read the decoded header and payload, and the dates for exp, nbf and iat.
- 3Check any warnings, such as alg “none” or a missing signature.
- 4Copy the decoded JSON if needed. Verify the signature in your own backend, never here.
Supported formats
Compact-serialised JWS tokens (header.payload.signature) with JSON header and payload. Encrypted tokens (JWE, five parts) cannot be decoded.
Privacy
This tool runs in your browser. The data you provide is processed on your device and is not sent to our servers.
Limitations
- The signature is NOT verified. The tool cannot tell you whether a token is authentic, current on the server, revoked, or meant for your application.
- Expiry and not-before status is calculated from your device clock, which may be wrong, and servers usually allow some clock skew.
- Encrypted JWTs (JWE) have five parts and an unreadable payload; they are reported as malformed here.
- Time claims must be numbers of seconds since 1970. Other values are shown as invalid.
- Other claims (iss, aud, sub, scope…) are displayed but not interpreted or validated.
FAQ
Does decoding mean the token is valid?
No. Decoding is not verification. Anyone can write a token whose payload says anything. Only checking the signature with the right secret or public key, plus validating claims such as issuer, audience and expiry, makes a token trustworthy.
Is my token sent to a server?
No. It is decoded in your browser and not transmitted. Even so, treat tokens like passwords and prefer expired or test tokens when you can.
What does alg “none” mean?
It declares an unsigned token. Servers must reject these unless they explicitly expect them; accepting them lets attackers forge any payload. The tool warns when it sees one.
Why does it say my token is expired when the server accepts it?
Your device clock may differ from the server's, or the server allows some leeway. The status here is a convenience based on your local time, not an authority.
Related tools
Base64 Decoder
Decode Base64 and URL-safe Base64 to text with UTF-8 support. Clear errors for invalid characters, length and padding.
JSON Formatter
Format, beautify and sort JSON with syntax highlighting. Pinpoints errors by line and column. Runs locally in your browser.
JSON Validator
Check whether JSON is valid and see the exact line and column of the first error, with a caret under the problem character.
JSON Minifier
Minify JSON by stripping whitespace to shrink payloads, with optional key sorting. Validated and processed locally in your browser.