That page doesn't exist. Search or drop a file below to find the tool you need.
What do you need to get done?
- Stays on this device
- No watermark
- Works offline
Drop a file here
or .
Open an app
Follow a recipe
Use one tool
JWT decoder
Paste a JWT and read what is inside: the header, the payload and every time claim such as exp, nbf and iat in your own time. You see at once whether the token has expired. The token is decoded in your browser and never uploaded.
How to decode a JWT
- 1Paste the token, with or without "Bearer " in front
- 2Read the header, payload and claims table
- 3Copy the payload as JSON if you need it
- Header, payload and expiry in plain view.
What happens to your token
- Nothing is uploaded.The token is decoded by your browser, on your own device.
- Expiry at a glance.A badge says whether the token expires, has expired or is not valid yet.
- Exact payloads.Large numeric IDs in the payload keep every digit.
What you can do
- Show the header and payload as formatted JSON, and colour the three parts of the token: header, payload and signature.
- Turn exp, nbf, iat and auth_time into dates in your time zone and in UTC, with a relative time such as "in 2 hours".
- Name common claims: issuer, subject, audience, token ID, authorized party, scope and session ID.
- Show the algorithm and type from the header, for example HS256 and JWT.
- Check the signature right below the result, if you have the secret or the public key.
Good to know
- Decoding is not verification. Anyone can read a JWT, so the content only counts as trustworthy once the signature is checked.
- Treat real tokens as passwords. Nothing leaves your browser here, but do not paste a live token into a tool you do not trust.
- Only signed tokens (JWS, three parts) are decoded. An encrypted token (JWE, five parts) is reported as such, not opened.
- The token must be copied whole, including both dots. A part that is not valid Base64URL or JSON gets its own error message.
Questions
How do I decode a JWT?
Paste the token into the box. The header and payload appear as readable JSON, and the claims table shows the dates in your time zone.
Is it safe to paste my JWT here?
Nothing is sent anywhere: the decoding runs in your browser. A real token is still a credential, so only use one you are allowed to share with your own device.
How can I see when a JWT expires?
Look at the badge under the input and at the exp row of the claims table. It shows the time in your zone and in UTC, and how long ago or how far ahead it is.
Does decoding check that the token is genuine?
No. To check that, enter the secret or public key in the "Verify the signature" box that appears below.