Decode a JSON Web Token and read its header, payload and expiry.
The JWT decoder splits a JSON Web Token into its header, payload and signature and shows them as readable JSON. The exp, iat and nbf claims are turned into dates, and you see at a glance whether the token has expired.
Decoding happens in your browser, so tokens are not sent anywhere. The signature is not verified: a decoded token proves nothing until your server checks it with the right key.
Pretty-printed JSON.
Expiry, issued at and not before, with relative times.
Valid or expired at a glance.
The token is decoded locally.
Usually not. A standard JWT is only Base64URL encoded and signed, so anyone can read the payload. Never put secrets in it.
The expiration time, in seconds since 1 January 1970 UTC. After it, the token must be rejected.
No. Verification needs the secret or public key and must be done by your server.
The header (algorithm and type), the payload (the claims) and the signature, separated by dots.