JWT Decoder
Paste a JSON Web Token below. Its header and payload decode instantly as readable JSON, with exp / iat timestamps converted to real dates.
Everything stays in your browser. Nothing is uploaded or stored — but remember a token's payload is only encoded, not encrypted.
How to decode a JWT
- Paste the token into the box above — the full
header.payload.signaturestring, exactly as issued. - Read the header. It usually names the signing algorithm (
alg, e.g. HS256) and the token type (typ: JWT). - Read the payload. These are the claims: who the token is for (
sub), when it expires (exp), custom fields your app added. - Check the dates. The time-claim table converts
exp,iat, andnbffrom Unix timestamps into readable UTC dates.
The three parts of a token
A JWT is three Base64url-encoded segments joined by dots. The header describes how the token was signed, the payload carries the claims, and the signature lets the issuer prove the first two haven't been tampered with. Base64url is an encoding, not encryption — anyone holding the token can decode the payload, which is why tokens must be treated like passwords.
Decoding is not verification
This tool only decodes. Verifying a signature requires the secret key (for HMAC algorithms like HS256) or the public key (for RSA/ECDSA algorithms like RS256) — and a secret key should never leave your server, let alone be pasted into a web page. A token that decodes cleanly here may still be forged, expired, or issued for someone else. Always verify on your backend before trusting a token.
- What is a JWT?
- A JSON Web Token is a compact, URL-safe string that carries claims (like a user ID or expiry time) between two parties. It has three dot-separated parts: header, payload, and signature.
- Does this tool verify the token's signature?
- No. Signature verification requires the secret key (or the public key for asymmetric tokens), which you should never paste into any website. This decoder only reads the header and payload — a successfully decoded token is not proof it is valid or trustworthy.
- Is it safe to paste my token here?
- Decoding happens entirely in your browser — your token is never uploaded or stored. But remember the payload is only encoded, not encrypted: anyone who has the token can read it, so treat tokens like passwords.
- What do exp, iat, and nbf mean?
- They are standard registered claims holding Unix timestamps: exp is when the token expires, iat is when it was issued, and nbf (not before) is the earliest time it becomes valid. This tool converts them to readable UTC dates automatically.
- Why does my token fail to decode?
- The usual causes are extra whitespace or line breaks, a missing segment (a real JWT has exactly three), or copying the token with surrounding quotes. Paste the raw token exactly as issued.
- Can this tool edit or create JWTs?
- No — it is a read-only decoder. Creating or signing tokens needs the secret key on your own server, which is exactly where signing belongs.
Kept alive by readers like you
Every tool in the codex is free. If they save you time, a small donation inscribes new pages.
DonateMore from the codex
JWT Decoder
Decode any JSON Web Token: header, payload, and readable exp/iat dates.
JSON Formatter
Validate, pretty-print, and minify JSON in your browser.
Open tool → LiveRegex Tester
Test regular expressions with live match highlighting.
Open tool → LiveBase64 Encoder
Encode and decode Base64, URL-safe too — full unicode support.
Open tool → LiveUnix Timestamp Converter
Turn epoch seconds into readable dates, and back.
Open tool → LiveURL Encoder / Decoder
Percent-encode URLs and parse query strings.
Open tool → LivePassword Generator
Strong random passwords and passphrases, 100% client-side.
Open tool → LiveMarkdown Previewer
Type Markdown, watch it render as HTML instantly.
Open tool → LiveColor Picker
Pick colors, copy HEX/RGB/HSL, check contrast ratios.
Open tool →