JWT Decoder

Decode a JSON Web Token to read its header and payload, and check when it expires.

Decoded on your device. This tool does not verify the signature — never trust a token's contents without verifying it on your server.

Runs in your browser — your data never leaves your device.

About the JWT Decoder

JSON Web Tokens (JWTs) carry login and permission data between apps and APIs. Paste a token to see its header and payload as formatted JSON, along with readable dates for the issued-at (iat), not-before (nbf) and expiry (exp) claims.

The token is decoded on your device, so it is safe to inspect tokens from your own projects. Signatures are not verified — do that on your server with the secret or public key.

How to use the JWT Decoder

  1. Paste the token (a leading Bearer is removed automatically).
  2. Read the header, payload and the status line showing the algorithm and whether the token has expired.
  3. Copy the header or payload JSON if needed.

How it works

A JWT is three Base64URL-encoded parts separated by dots: header, payload and signature. The first two are decoded as UTF-8 JSON. Time claims are Unix timestamps in seconds and are shown in your local time.

Examples

  • The well-known sample token from jwt.io decodes to {"sub":"1234567890","name":"John Doe","iat":1516239022} — issued 18 January 2018.

Frequently asked questions

Is it safe to paste a token here?

The token is only decoded in your browser and is not sent to our server. Still, treat live tokens like passwords and avoid sharing them.

Why is the signature not checked?

Verifying needs the secret or public key, which should stay on your server. Decoding only shows what the token claims.

Category: Developer Tools · Free to use · Last updated Oct 8, 2026