Developer Tools
JWT Decoder
Decode any JWT to inspect its header and payload claims, with expiry dates explained.
Signature NOT verified — this tool only decodes the token so you can inspect it. Never paste production secrets; anyone holding the token can read it.
Paste a token and press Decode token.
What is a JWT decoder?
A JSON Web Token (JWT) is three Base64URL-encoded parts joined by dots: a header (algorithm and token type), a payload (claims like user id and expiry), and a signature. Servers pass JWTs around for authentication, and when something goes wrong — an expired session, a wrong role, a clock-skew rejection — the fastest diagnosis is to look inside the token. This decoder splits the parts, decodes the header and payload into readable JSON, and translates the exp, iat, and nbf timestamp claims into human dates with plain-English validity notes.
How to use this tool
- Paste the full JWT (header.payload.signature) into the token box.
- Press Decode token.
- Read the header and payload as pretty-printed JSON.
- Check the time-claims card: expiry date and whether the token is expired, when it was issued, and whether it is not yet valid.
Key features
- Correct Base64URL decoding with padding repair and UTF-8 support for non-ASCII claims.
- Pretty-printed header and payload JSON in readable cards.
- Automatic exp / iat / nbf conversion to local dates, with EXPIRED / valid / not-yet-valid annotations.
- Graceful errors for truncated tokens, non-JSON parts, and malformed Base64URL.
- Repeated prominent warnings that the signature is never verified — decoding is inspection, not authentication.
Common use cases
- Debugging "unauthorized" errors: checking whether the token actually expired.
- Auth development: verifying the claims your login endpoint puts into tokens.
- Role issues: confirming the roles or scopes claim contains what the API expects.
- Clock skew: comparing iat/exp against your machine's time when tokens are rejected.
- Learning: seeing the real structure of the tokens tutorials talk about.
Practical tips
- Never paste a production token with real privileges into any online tool — the payload is only Base64-encoded, not encrypted, so anyone can read it.
- A decoded token tells you nothing about authenticity; only cryptographic signature verification by your server does that.
- exp is in seconds since epoch, not milliseconds — a 13-digit "expiry" is a bug in whatever issued the token.
- If a token is valid but rejected, check nbf (not-before) and your server's clock before anything else.
- Keep tokens out of URLs where possible — they leak into logs and browser history.
Frequently Asked Questions
What are the three parts of a JWT?
Header (signing algorithm and token type), payload (the claims, like subject and expiry), and signature — each Base64URL-encoded and joined by dots. This tool decodes the first two.
Does decoding verify the token's signature?
No, and that is stated prominently in the tool. Decoding only reveals the contents; proving the token is authentic and untampered requires cryptographic verification with the issuer's secret or public key.
What do exp, iat, and nbf mean?
exp is when the token expires, iat is when it was issued, and nbf is the earliest time it becomes valid — all as seconds since the Unix epoch. The tool converts them to readable dates and flags expired or not-yet-valid tokens.
Is the payload encrypted?
No. The payload is merely Base64URL-encoded, which anyone can decode — including with this tool. Never put secrets in JWT claims.
Why does my token fail to decode?
Usually it is truncated (missing a part), has whitespace or line breaks pasted in, or is not a JWT at all. The tool reports which part failed so you can fix the paste.