The jwt.io example token
Header {"alg": "HS256", "typ": "JWT"}; payload with sub 1234567890, name John Doe and iat 1516239022 (18 January 2018).
Decode a JSON Web Token to read its header and claims, with expiry times in plain language.
Runs in your browser — nothing you enter is sent to a server.
A JSON Web Token has three parts separated by dots: a header, a payload of claims, and a signature. The first two are Base64URL-encoded JSON, so anyone can read them. Paste a token (with or without “Bearer”) to see both, plus the standard claims — issuer, subject, audience and the issued, not-before and expiry times — in plain language.
Decoding happens in your browser. The signature isn't verified: that needs the signing secret or public key, which you should never paste into any website.
base64url(header) . base64url(payload) . signature
exp, nbf and iat are Unix timestamps in seconds.
Header {"alg": "HS256", "typ": "JWT"}; payload with sub 1234567890, name John Doe and iat 1516239022 (18 January 2018).
An exp in the past shows “Expired … ago”, so you can spot why an API rejects a token.
The token isn't sent anywhere, but treat live tokens like passwords: anyone who has one can use it until it expires. Prefer test or expired tokens.
Usually not — a signed JWT is only encoded, so never put secrets in its payload. Encrypted tokens (JWE) have five parts and can't be read without the key.
Checking a signature proves the token wasn't changed, but it needs the key. Do that in your server code with a JWT library.
Encode text to Base64 or decode Base64 to text, with full Unicode support and URL-safe output.
Developer Tools
Format, validate and minify JSON, with the exact line and column of any error.
Developer Tools
Convert Unix timestamps to dates in UTC and your time zone, and dates back to timestamps.
Developer Tools