Skip to content

JWT Decoder

Decode a JSON Web Token to read its header and claims, with expiry times in plain language.

Runs in your browser — nothing you enter is sent to a server.

How the JWT Decoder works

A JSON Web Token has three parts separated by dots: a header, a payload of claims, and a signature. The first two are Base64URL-encoded JSON, so anyone can read them. Paste a token (with or without “Bearer”) to see both, plus the standard claims — issuer, subject, audience and the issued, not-before and expiry times — in plain language.

Decoding happens in your browser. The signature isn't verified: that needs the signing secret or public key, which you should never paste into any website.

Formula

base64url(header) . base64url(payload) . signature

exp, nbf and iat are Unix timestamps in seconds.

Examples

The jwt.io example token

Header {"alg": "HS256", "typ": "JWT"}; payload with sub 1234567890, name John Doe and iat 1516239022 (18 January 2018).

Expiry

An exp in the past shows “Expired … ago”, so you can spot why an API rejects a token.

Frequently asked questions

Is it safe to paste a token here?

The token isn't sent anywhere, but treat live tokens like passwords: anyone who has one can use it until it expires. Prefer test or expired tokens.

Is a JWT encrypted?

Usually not — a signed JWT is only encoded, so never put secrets in its payload. Encrypted tokens (JWE) have five parts and can't be read without the key.

Why does it say the signature isn't verified?

Checking a signature proves the token wasn't changed, but it needs the key. Do that in your server code with a JWT library.

Base64 Encoder & Decoder

Encode text to Base64 or decode Base64 to text, with full Unicode support and URL-safe output.

Developer Tools

JSON Formatter

Format, validate and minify JSON, with the exact line and column of any error.

Developer Tools

Unix Timestamp Converter

Convert Unix timestamps to dates in UTC and your time zone, and dates back to timestamps.

Developer Tools