🎫

JWT Decoder

Decode a JWT to read its header and payload, inspect claims and check expiry. Runs entirely in your browser — tokens are never transmitted.

✓ Free forever✓ No signup✓ 100% private — runs in your browser
JWT Decoder
Decode and inspect JSON Web Tokens. View header, payload, and expiry status. Never transmits your token.
JWT Token
Header
—
Payload
—
Status

A JSON Web Token is three Base64url segments separated by dots: a header describing the signing algorithm, a payload of claims, and a signature. The first two are merely encoded, not encrypted, so anyone holding a token can read everything in it.

How to use the JWT Decoder

  1. Paste the full JWT, including both dots
  2. Read the decoded header to see the signing algorithm
  3. Read the payload claims
  4. Check exp against the current time to see whether the token is still valid

A JWT payload is public

This is the single most important thing to understand about JWTs. The payload is Base64url-encoded, which is reversible by anyone — including this page, with no key involved.

The signature guarantees the token has not been modified. It does nothing to keep the contents secret. Never put anything confidential in a JWT payload: no passwords, no personal data beyond what the client is allowed to see, no internal system details.

Treat a token's contents as though they were printed on the outside of the envelope, because effectively they are.

The standard claims

  • iss issuer — who created the token.
  • sub subject — who it is about, usually a user ID.
  • aud audience — who it is intended for.
  • exp expiry — Unix timestamp after which it must be rejected.
  • iat issued at — when it was created.
  • nbf not before — when it becomes valid.

Timestamps are Unix seconds, not milliseconds. Use the Unix Timestamp Converter to read them. Note that decoding shows whether a token has expired, but only the server can confirm the signature is genuine — a decoder cannot validate a token without the signing key.

Frequently asked questions

Is it safe to paste a JWT here?

Decoding happens entirely in your browser and nothing is transmitted. That said, a live token is a credential — treat it with the same care as a password and prefer expired or test tokens where possible.

Can this verify the signature?

No. Verification requires the secret or public key, which only the issuing server holds. Decoding shows you the contents; it does not prove the token is authentic.

Is the payload encrypted?

No — only Base64url encoded, which anyone can reverse. Never store confidential data in a JWT payload.

What does alg: none mean?

An unsigned token. It was a serious vulnerability in several early libraries, which accepted alg: none and skipped verification entirely. Any correct implementation rejects it.