ToolRecipe

What do you need to get done?

Drop a file here

or .

Open an app

Follow a recipe

All recipes

Use one tool

All tools

JWT decoder

Paste a JWT and read what is inside: the header, the payload and every time claim such as exp, nbf and iat in your own time. You see at once whether the token has expired. The token is decoded in your browser and never uploaded.

How to decode a JWT

  1. 1Paste the token, with or without "Bearer " in front
  2. 2Read the header, payload and claims table
  3. 3Copy the payload as JSON if you need it
  4. Header, payload and expiry in plain view.

What happens to your token

  • Nothing is uploaded.The token is decoded by your browser, on your own device.
  • Expiry at a glance.A badge says whether the token expires, has expired or is not valid yet.
  • Exact payloads.Large numeric IDs in the payload keep every digit.

What you can do

  • Show the header and payload as formatted JSON, and colour the three parts of the token: header, payload and signature.
  • Turn exp, nbf, iat and auth_time into dates in your time zone and in UTC, with a relative time such as "in 2 hours".
  • Name common claims: issuer, subject, audience, token ID, authorized party, scope and session ID.
  • Show the algorithm and type from the header, for example HS256 and JWT.
  • Check the signature right below the result, if you have the secret or the public key.

Good to know

  • Decoding is not verification. Anyone can read a JWT, so the content only counts as trustworthy once the signature is checked.
  • Treat real tokens as passwords. Nothing leaves your browser here, but do not paste a live token into a tool you do not trust.
  • Only signed tokens (JWS, three parts) are decoded. An encrypted token (JWE, five parts) is reported as such, not opened.
  • The token must be copied whole, including both dots. A part that is not valid Base64URL or JSON gets its own error message.

Questions

How do I decode a JWT?

Paste the token into the box. The header and payload appear as readable JSON, and the claims table shows the dates in your time zone.

Is it safe to paste my JWT here?

Nothing is sent anywhere: the decoding runs in your browser. A real token is still a credential, so only use one you are allowed to share with your own device.

How can I see when a JWT expires?

Look at the badge under the input and at the exp row of the claims table. It shows the time in your zone and in UTC, and how long ago or how far ahead it is.

Does decoding check that the token is genuine?

No. To check that, enter the secret or public key in the "Verify the signature" box that appears below.

How it works

Small tools that run in your browser.

Four steps

  1. Start with a file or a task

    Drop a file, search, or pick a task.

  2. The tool opens in a window

    Open as many as you like, side by side as tabs.

  3. Results collect on the right

    Drag a result into the next tool.

  4. Save when you're done

    Saved files go to your downloads.

Who uses what

Tool sets for common jobs.

Put a tool on your home screen

The icon opens that tool, like an app.

iPhone and iPad

  1. Open the tool in Safari.
  2. Tap Share (the square with the arrow).
  3. Choose “Add to Home Screen”, then Add.

Android

  1. Open the tool in Chrome.
  2. Tap the menu (⋮) at the top right.
  3. Choose “Add to Home screen” or “Install app”.

Computer

  1. Open the tool in Chrome or Edge.
  2. Click the install icon in the address bar.
  3. Choose Install.

Skills

Claude skills we use ourselves, one job each.