The Magic Codex

JWT Decoder

Paste a JSON Web Token below. Its header and payload decode instantly as readable JSON, with exp / iat timestamps converted to real dates.

Everything stays in your browser. Nothing is uploaded or stored — but remember a token's payload is only encoded, not encrypted.

How to decode a JWT

  1. Paste the token into the box above — the full header.payload.signature string, exactly as issued.
  2. Read the header. It usually names the signing algorithm (alg, e.g. HS256) and the token type (typ: JWT).
  3. Read the payload. These are the claims: who the token is for (sub), when it expires (exp), custom fields your app added.
  4. Check the dates. The time-claim table converts exp, iat, and nbf from Unix timestamps into readable UTC dates.

The three parts of a token

A JWT is three Base64url-encoded segments joined by dots. The header describes how the token was signed, the payload carries the claims, and the signature lets the issuer prove the first two haven't been tampered with. Base64url is an encoding, not encryption — anyone holding the token can decode the payload, which is why tokens must be treated like passwords.

Decoding is not verification

This tool only decodes. Verifying a signature requires the secret key (for HMAC algorithms like HS256) or the public key (for RSA/ECDSA algorithms like RS256) — and a secret key should never leave your server, let alone be pasted into a web page. A token that decodes cleanly here may still be forged, expired, or issued for someone else. Always verify on your backend before trusting a token.

What is a JWT?
A JSON Web Token is a compact, URL-safe string that carries claims (like a user ID or expiry time) between two parties. It has three dot-separated parts: header, payload, and signature.
Does this tool verify the token's signature?
No. Signature verification requires the secret key (or the public key for asymmetric tokens), which you should never paste into any website. This decoder only reads the header and payload — a successfully decoded token is not proof it is valid or trustworthy.
Is it safe to paste my token here?
Decoding happens entirely in your browser — your token is never uploaded or stored. But remember the payload is only encoded, not encrypted: anyone who has the token can read it, so treat tokens like passwords.
What do exp, iat, and nbf mean?
They are standard registered claims holding Unix timestamps: exp is when the token expires, iat is when it was issued, and nbf (not before) is the earliest time it becomes valid. This tool converts them to readable UTC dates automatically.
Why does my token fail to decode?
The usual causes are extra whitespace or line breaks, a missing segment (a real JWT has exactly three), or copying the token with surrounding quotes. Paste the raw token exactly as issued.
Can this tool edit or create JWTs?
No — it is a read-only decoder. Creating or signing tokens needs the secret key on your own server, which is exactly where signing belongs.

More from the codex