Developer Tools

JWT Decoder

Decode any JWT to inspect its header and payload claims, with expiry dates explained.

Signature NOT verified — this tool only decodes the token so you can inspect it. Never paste production secrets; anyone holding the token can read it.
Paste a token and press Decode token.

What is a JWT decoder?

A JSON Web Token (JWT) is three Base64URL-encoded parts joined by dots: a header (algorithm and token type), a payload (claims like user id and expiry), and a signature. Servers pass JWTs around for authentication, and when something goes wrong — an expired session, a wrong role, a clock-skew rejection — the fastest diagnosis is to look inside the token. This decoder splits the parts, decodes the header and payload into readable JSON, and translates the exp, iat, and nbf timestamp claims into human dates with plain-English validity notes.

How to use this tool

  1. Paste the full JWT (header.payload.signature) into the token box.
  2. Press Decode token.
  3. Read the header and payload as pretty-printed JSON.
  4. Check the time-claims card: expiry date and whether the token is expired, when it was issued, and whether it is not yet valid.

Key features

Common use cases

Practical tips

Frequently Asked Questions

What are the three parts of a JWT?
Header (signing algorithm and token type), payload (the claims, like subject and expiry), and signature — each Base64URL-encoded and joined by dots. This tool decodes the first two.
Does decoding verify the token's signature?
No, and that is stated prominently in the tool. Decoding only reveals the contents; proving the token is authentic and untampered requires cryptographic verification with the issuer's secret or public key.
What do exp, iat, and nbf mean?
exp is when the token expires, iat is when it was issued, and nbf is the earliest time it becomes valid — all as seconds since the Unix epoch. The tool converts them to readable dates and flags expired or not-yet-valid tokens.
Is the payload encrypted?
No. The payload is merely Base64URL-encoded, which anyone can decode — including with this tool. Never put secrets in JWT claims.
Why does my token fail to decode?
Usually it is truncated (missing a part), has whitespace or line breaks pasted in, or is not a JWT at all. The tool reports which part failed so you can fix the paste.