JWT decoder.
Paste a token and read what's inside: header, payload, and when it expires. It never leaves this tab.
- Free
- No signup
- Runs in your browser
The token is decoded in this tab and never sent anywhere. The signature is not verified: that needs the secret or public key, and belongs on your server.
Signature, HS256, not verified
_ZH-PMYDgl8belqLAkuiVd6QTlrX8Nx6hpljurdhUDY
How it works.
- 1
Paste a JWT. A Bearer prefix from a header is fine, it gets stripped.
- 2
Read the header and payload as formatted JSON, with exp, iat and nbf as real dates.
- 3
See at a glance whether the token is valid, expired, or not valid yet.
What's inside a JWT
A JSON Web Token is three base64url parts joined by dots. The header says how it was signed, the payload holds the claims (who the user is, when the token expires), and the signature proves nobody changed the first two.
The header and payload are only encoded, not encrypted. Anyone holding the token can read them, exactly like this page does. Keep secrets out of the payload.
Decoding is not verifying
Checking the signature needs the secret for HS256 or the public key for RS256 and ES256. That check belongs on your server, done by a maintained library such as jose, and a server should never trust a payload it has not verified.
This decoder never asks for a key. It reads the token so you can debug it: why a request gets a 401, which audience a token is for, or whether it expired five minutes ago.
Questions, answered.
How do I decode a JWT?
Paste it into the box above. The header and payload show up as formatted JSON, and the standard claims are listed with readable dates and the token's expiry status.
Is it safe to paste my JWT here?
The token is decoded by JavaScript in this tab and no request is made with it. Still, a live token works for whoever holds it until it expires, so treat it like a password anywhere else.
What do exp, iat and nbf mean?
They are times in seconds since 1 January 1970, UTC. exp is when the token expires, iat is when it was issued, and nbf is the moment before which it must be rejected.
Why does my token count as expired when it was just issued?
Usually the server clocks disagree. Most libraries allow a few seconds of leeway for that. Also check that exp is in seconds: a value in milliseconds lands tens of thousands of years in the future.
Can I decode a JWT without the secret?
Yes. Anyone can read the header and payload. The secret or public key is only needed to verify the signature, which proves the token is genuine.
More free tools.
All tools- Base64 DecodeDecode or encode base64, with UTF-8, URL-safe mode and file to data URL.
- Unix Timestamp ConverterEpoch time to date and back, with seconds and milliseconds detected for you.
- JSON FormatterPretty print, sort keys or minify JSON. Big numbers stay exact.
- UUID GeneratorBulk UUID v4, v7, GUID and NanoID, formatted the way you need.
Debugging tokens? Skip writing them.
Let people sign in with Google.. Add API keys my users can create and revoke.. Send a welcome email right after signup.Hype Stack starters come with sign-in already wired through Better Auth or WorkOS, on a free full-stack template. Your agent starts on the product, not the session code.