Skip to JWT decoder
Edwin Lab

JWT Decoder

Inspect a compact JSON Web Token header and payload, and see when its time claims apply. The token stays in this browser.

Decoded only. Signature not verified. Decoding shows token contents; it does not prove who issued the token or whether a service will accept it.

Input limit: 5 MiB UTF-8. Paste the token only; do not include a Bearer prefix. Content is processed locally and is not uploaded.

Ready. Paste a compact JWT and select Decode.

How to decode a JWT

  1. Paste a compact token with three dot-separated segments. Remove any Bearer prefix.
  2. Select Decode to inspect the JSON header, payload, and exp, nbf, and iat claims.
  3. Copy the header or payload if you need to inspect it elsewhere.

JWT uses Base64URL-encoded segments; encoding is not encryption. For example, a decoded header might contain {"alg":"none","typ":"JWT"}, while its payload can contain a subject and NumericDate claims.

Decoding is not signature verification

This tool only decodes the header and payload. It does not verify a signature, check an issuer or audience, or establish that a server will accept the token. A token marked expired here may be rejected by an application, while a token whose displayed time claims look current still requires verification and authorization checks by the receiving service.

exp means the token must not be accepted on or after its expiration time. nbf sets the time before which it must not be accepted. iat records when it was issued. These NumericDate values use seconds, and the displayed current-time comparison uses this device's clock.

Example token

Select Load example to inspect a synthetic token with a subject, issue time, not-before time, and expiration time. Its alg: "none" header and empty signature remain unverified.

Frequently asked questions

Does this verify the signature?

No. It decodes the header and payload only. Signature status always remains Unverified, regardless of the alg value or whether a signature segment is present.

Are my tokens uploaded?

No. Decoding happens in your browser. This page does not send the token to an API, add it to the URL, or save it in browser storage. Treat tokens as sensitive credentials and avoid sharing them.

Related developer tools

Convert a NumericDate with the Unix Timestamp Converter, inspect JSON with the JSON Validator & Formatter, or browse the Developer Tools directory.