JWT Decoder
Inspect JSON Web Token claims, header algorithms, and expiration status in your browser. No tokens are sent over the network.
Decode only. This shows what's inside a token but does not verify its signature. Avoid pasting live production tokens on shared computers.
Dates in this token
- Issued at
(iat) - 1/18/2018, 1:30:22 AM · 1516239022
- Expires
(exp) - 5/18/2033, 3:33:19 AM · 1999999999
Header
{
"alg": "HS256",
"typ": "JWT"
}Payload (claims)
{
"sub": "usr_98284",
"name": "Alex Miller",
"role": "admin",
"iat": 1516239022,
"exp": 1999999999
}How to use JWT Decoder
- Paste your encoded JWT token into the input field.
- Inspect the decoded Header, Payload claims, and Signature segments.
- Check expiration date status and issued-at timestamps.
About JWT Decoder
Decode a JSON Web Token to read its header and payload. The tool shows the signing algorithm, all claims, and turns timestamps like iat and exp into readable dates, with a clear expired or not-expired status.
Related tools: JSON Formatter & Validator, Base64 Encoder / Decoder, URL Encoder / Decoder, Regex Tester
What is inside a JWT
A JWT has three parts separated by dots: a header that names the signing algorithm, a payload of claims such as user ID, roles, and expiry, and a signature. The header and payload are only Base64URL-encoded, so anyone holding the token can read them.
Time claims are Unix timestamps in seconds. The decoder converts iat (issued at), nbf (not valid before), exp (expires), and auth_time into dates in your local time zone.
Decoding is not verifying
This tool does not check the signature, so it cannot tell you whether a token is genuine or has been tampered with. Verification needs the secret or public key and should happen on your server.
Because tokens grant access, avoid pasting live production tokens on shared computers. Decoding happens in your browser and nothing is sent anywhere.
Common uses
- Debugging login issues
- Check whether a token has expired or is missing a role or scope.
- Checking clock problems
- Compare iat, nbf, and exp against your local time.
- Reviewing integrations
- Confirm which claims an identity provider sends.
- Learning JWTs
- See how header, payload, and signature fit together.
Questions about JWT Decoder
- Does decoding verify the token signature?
- No. Client-side decoding inspects payload and header claims only. Signature verification requires secret keys on your backend authentication server.
- Is my JWT token transmitted to a server?
- No. Token decoding runs entirely in your local browser JavaScript thread.
- Why is my token shown as expired?
- Its exp time is in the past compared with your computer's clock. If the clock is wrong, the status will be too.
- Can I edit a token here?
- No. Changing the payload would invalidate the signature, so editing is not offered.
- Which algorithms are supported?
- Any. Decoding only reads the header and payload, so tokens signed with HS256, RS256, ES256, or any other algorithm can be inspected.
Comments
Questions, ideas, or a bug in JWT Decoder? Let us know.