JWT Decoder
Decode a JWT and inspect its header, payload and expiry in your browser.
Runs in your browser. Nothing is uploaded.
What is JWT Decoder?
A JSON Web Token, or JWT, is a compact string that web applications use to carry identity and permissions between a client and a server. It looks like three blocks of random characters separated by dots. The first block is the header, which says how the token is signed. The second is the payload, which holds the claims such as who the user is, who issued the token and when it expires. The third is the signature.
This JWT decoder reads a token and shows you the header and payload as formatted JSON, so you can see exactly what is inside. It turns the issued-at, not-before and expiry timestamps into readable dates in both UTC and your own time zone, with a live countdown, and shows a badge telling you whether the token is currently valid, expired or not yet valid. It also lists the meaning of the standard claims it finds, and warns you about risky headers such as the unsigned algorithm none.
Decoding happens entirely in your browser. A JWT is often a live credential, so the token you paste is never uploaded, never logged and never remembered by this tool, not even in your browser storage. The decoder does not verify signatures: it shows what a token says, not whether the token is genuine, so never rely on it to decide who to trust.
How to use
- Paste your JWT into the box, or click Load sample to try an example. A leading Bearer prefix, quotes and line breaks are cleaned up for you.
- Read the status badge to see whether the token is valid, expired or not yet valid right now.
- Check the header and payload JSON, and the dates table for the issued-at, not-before and expiry times.
- Use the Copy buttons to copy the header, the payload or the signature.
- If you see a warning about the algorithm, treat the token with caution.
Example
Input
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
Output
Header: {"alg":"HS256","typ":"JWT"}
Payload: {"sub":"1234567890","name":"John Doe","iat":1516239022}
Issued at: 2018-01-18T01:30:22.000ZFrequently asked questions
- Is it safe to paste my JWT here?
- Yes, as far as this site is concerned: the token is decoded in your browser and never sent anywhere or saved. Still, treat live tokens as passwords and prefer expired or test tokens when you can.
- Does this tool verify the signature?
- No. It decodes and displays the token only. Verifying a signature needs the secret or public key, and a decoded token that looks fine is not proof that it is genuine.
- Why does my token say expired?
- The exp claim is a time in seconds since 1970 (Unix time). If that time is before your device clock now, the token has expired. The dates table shows the exact time in UTC and in your own time zone.
- What does alg none mean?
- It means the token is not signed at all. Anyone could have created or edited it, so a server should never accept it as proof of identity. The decoder warns you whenever it sees it.
Related tools
- Base64 Encode / DecodeBase64 encode and decode text with full UTF-8 and URL-safe support.
- JSON Formatter & ValidatorFormat, minify and validate JSON online with line-accurate error messages.
- Unix Timestamp ConverterConvert Unix timestamps to dates and back, in any timezone.
- UUID GeneratorGenerate UUID v4 and v7 in bulk, and validate any UUID.