🔐 JWT Decoder

Paste a JSON Web Token to read its header and payload instantly, with human-readable dates for expiry and issued-at. Decoding only — nothing is uploaded and no secret is needed. Runs 100% in your browser.

🔒 Private · Free · No upload

How to use 🔐 JWT Decoder

  1. 1. Paste a JSON Web Token (three Base64URL parts separated by dots) into the box, or click Load sample to see how a decoded token looks.
  2. 2. The token decodes instantly as you type. Read the HEADER card for the algorithm and type, and the PAYLOAD card for the claims.
  3. 3. Check the dates under the payload: issued at (iat), not before (nbf) and expires (exp) are shown in your local time, with an expired or valid label.
  4. 4. Press Copy on either card to copy the formatted JSON, or click Clear to remove the token from the page when you are done.

Frequently asked questions

Is the JWT decoder free to use?

Yes, it is free with no sign-up and no limit on how many tokens you decode. It only reads the header and payload, so it works with tokens from any provider, including Auth0, Firebase, AWS Cognito, Okta or your own backend.

Is it safe to paste a JWT into this decoder?

The token is decoded with JavaScript in your browser and is never sent to our server. Still, treat live access tokens like passwords: prefer expired or test tokens, clear the box when finished, and never share a token that still grants access.

How do I check when a JWT expires?

Paste the token and look under the payload card. If it contains an exp claim, the decoder converts the Unix timestamp to a readable date and time in your time zone and marks the token as expired or still valid.

Does this JWT decoder verify the token’s signature?

No. It decodes only. The signature is shown shortened and labeled as not verified, because checking it requires the secret or public key, which should stay on your server. Use your backend’s JWT library to verify tokens before trusting them.

Why does the decoder say my token does not look like a JWT?

A JWT needs at least a header and payload separated by a dot. Make sure you copied the whole token without the Bearer prefix, quotes or line breaks. If the header or payload isn’t valid Base64URL JSON, the decoder shows which part failed.

What JWT formats does the decoder support?

It reads standard signed JWTs (JWS) with Base64URL-encoded JSON in the header and payload, whatever the algorithm, such as HS256, RS256 or ES256. Encrypted tokens (JWE) can’t be read without the key, so their payload won’t decode.

Related guides

🛠️ All text & developer guides and tools →