JWT Decoder
Decode JSON Web Tokens and inspect header, payload and expiry.
The signature is not verified — that requires the signing key, which should never be pasted into a website.
About JWT Decoder
Paste a JSON Web Token to see its decoded header and payload. Standard claims such as exp, iat and nbf are converted to readable dates and the tool tells you whether the token is currently valid in time. Decoding happens locally, which matters because tokens are credentials.
How it works
-
1
Paste a JWT (the three dot-separated parts).
-
2
Read the decoded header, payload and time-based claims.
-
3
Copy any section as formatted JSON.
Frequently asked questions
Does this verify the signature?
No. Verifying requires the secret or public key, which should never be pasted into a website. The tool only decodes the token.
Is it safe to paste a production token?
The token is decoded in your browser and never sent anywhere. Still, treat live tokens as passwords and prefer expired ones for debugging.