JWT Decoder
Token
Header
Example{
"alg": "HS256",
"typ": "JWT"
}Payload
Example{
"sub": "1234567890",
"name": "John Doe",
"iat": 1516239022
}Signature
ExampleSflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5cThe signature is not checked here: that needs the signing secret or the issuer's public key, so do not trust these claims until your application has verified the token.
About
A JSON Web Token (JWT) has three Base64url-encoded parts separated by dots: header, payload, and signature. This tool decodes the header and payload and shows the signature as it is, without verifying it - so it cannot tell you whether a token is authentic.
How to use
1.
Paste a JWT into the Token field - a "Bearer " prefix and line breaks are removed automatically
2.
Read the decoded Header and Payload panels - if the token cannot be decoded, the reason appears under the Token field
3.
Check the status next to the Token title and the Time claims panel to see when the token was issued and when it expires
Common uses
▸
Debugging authentication issues by inspecting token claims
▸
Checking token expiry during development without decoding it in code
▸
Seeing which signing algorithm (alg) and claims a token carries
Similar tools
Frequently asked questions
Does this validate the JWT signature?
No. It decodes the header and payload but does not verify the signature, so it cannot tell you whether a token is genuine or has been tampered with. Verification needs the HMAC secret or the issuer's public key - do it with a JWT library in the application that accepts the token.
Why won't my token decode?
A JWT must have exactly three parts separated by dots, and its header and payload must be Base64url-encoded JSON objects. The message under the Token field says which check failed. An Authorization: Bearer prefix, spaces and line breaks are removed for you, so a token copied from a request header or a wrapped log line still decodes.
What are the three parts of a JWT?
A JWT has three Base64url-encoded sections separated by dots: the header (algorithm and token type), the payload (claims), and the signature. Encrypted tokens (JWE) have five parts and cannot be read without the decryption key.
What do "exp", "nbf" and "iat" mean?
"exp" is the expiration time, "nbf" the time before which the token must not be accepted, and "iat" the time it was issued - all Unix timestamps in seconds. The Time claims panel shows each as a readable date in your local time and in UTC, and flags values that look like milliseconds. The status next to the Token title shows whether the token is expired, not yet valid, or currently valid.
Is it safe to paste a real token here?
Decoding happens entirely in your browser and the token is never sent to any server. Still, a token can carry sensitive claims (user IDs, roles, emails), and one that has not expired grants access, so avoid pasting it on a shared computer.