JWT decoder

Decode a JSON Web Token and read its header, payload and expiry.

  • Development
  • 100% free
  • No sign-up
  • Runs in your browser
JWT decoder

What is the jwt decoder?

The JWT decoder splits a JSON Web Token into its header, payload and signature and shows them as readable JSON. The exp, iat and nbf claims are turned into dates, and you see at a glance whether the token has expired.

Decoding happens in your browser, so tokens are not sent anywhere. The signature is not verified: a decoded token proves nothing until your server checks it with the right key.

How to use the jwt decoder

  1. 1Paste the JWT (a leading Bearer is removed).
  2. 2Read the header, the payload and the dates.
  3. 3Copy the parts you need.

Features

Header and payload

Pretty-printed JSON.

Readable dates

Expiry, issued at and not before, with relative times.

Expiry status

Valid or expired at a glance.

Private

The token is decoded locally.

Frequently asked questions

Is a JWT encrypted?

Usually not. A standard JWT is only Base64URL encoded and signed, so anyone can read the payload. Never put secrets in it.

What does exp mean?

The expiration time, in seconds since 1 January 1970 UTC. After it, the token must be rejected.

Does this tool verify the signature?

No. Verification needs the secret or public key and must be done by your server.

What are the three parts of a JWT?

The header (algorithm and type), the payload (the claims) and the signature, separated by dots.