How to decode a JWT
- Paste a compact token with three dot-separated segments. Remove any
Bearerprefix. - Select Decode to inspect the JSON header, payload, and
exp,nbf, andiatclaims. - Copy the header or payload if you need to inspect it elsewhere.
JWT uses Base64URL-encoded segments; encoding is not encryption. For example, a decoded header might contain {"alg":"none","typ":"JWT"}, while its payload can contain a subject and NumericDate claims.
Decoding is not signature verification
This tool only decodes the header and payload. It does not verify a signature, check an issuer or audience, or establish that a server will accept the token. A token marked expired here may be rejected by an application, while a token whose displayed time claims look current still requires verification and authorization checks by the receiving service.
exp means the token must not be accepted on or after its expiration time. nbf sets the time before which it must not be accepted. iat records when it was issued. These NumericDate values use seconds, and the displayed current-time comparison uses this device's clock.
Example token
Select Load example to inspect a synthetic token with a subject, issue time, not-before time, and expiration time. Its alg: "none" header and empty signature remain unverified.
Frequently asked questions
Does this verify the signature?
No. It decodes the header and payload only. Signature status always remains Unverified, regardless of the alg value or whether a signature segment is present.
Are my tokens uploaded?
No. Decoding happens in your browser. This page does not send the token to an API, add it to the URL, or save it in browser storage. Treat tokens as sensitive credentials and avoid sharing them.
Related developer tools
Convert a NumericDate with the Unix Timestamp Converter, inspect JSON with the JSON Validator & Formatter, or browse the Developer Tools directory.