Skip to content
Swizztool

JWT Decoder

Inspect JSON Web Token claims, header algorithms, and expiration status in your browser. No tokens are sent over the network.

Decode only. This shows what's inside a token but does not verify its signature. Avoid pasting live production tokens on shared computers.

Not expired · 5/18/2033, 3:33:19 AM

Dates in this token

Issued at (iat)
1/18/2018, 1:30:22 AM · 1516239022
Expires (exp)
5/18/2033, 3:33:19 AM · 1999999999

Header

{
  "alg": "HS256",
  "typ": "JWT"
}

Payload (claims)

{
  "sub": "usr_98284",
  "name": "Alex Miller",
  "role": "admin",
  "iat": 1516239022,
  "exp": 1999999999
}

How to use JWT Decoder

  1. Paste your encoded JWT token into the input field.
  2. Inspect the decoded Header, Payload claims, and Signature segments.
  3. Check expiration date status and issued-at timestamps.

About JWT Decoder

Decode a JSON Web Token to read its header and payload. The tool shows the signing algorithm, all claims, and turns timestamps like iat and exp into readable dates, with a clear expired or not-expired status.

Related tools: JSON Formatter & Validator, Base64 Encoder / Decoder, URL Encoder / Decoder, Regex Tester

What is inside a JWT

A JWT has three parts separated by dots: a header that names the signing algorithm, a payload of claims such as user ID, roles, and expiry, and a signature. The header and payload are only Base64URL-encoded, so anyone holding the token can read them.

Time claims are Unix timestamps in seconds. The decoder converts iat (issued at), nbf (not valid before), exp (expires), and auth_time into dates in your local time zone.

Decoding is not verifying

This tool does not check the signature, so it cannot tell you whether a token is genuine or has been tampered with. Verification needs the secret or public key and should happen on your server.

Because tokens grant access, avoid pasting live production tokens on shared computers. Decoding happens in your browser and nothing is sent anywhere.

Common uses

Debugging login issues
Check whether a token has expired or is missing a role or scope.
Checking clock problems
Compare iat, nbf, and exp against your local time.
Reviewing integrations
Confirm which claims an identity provider sends.
Learning JWTs
See how header, payload, and signature fit together.

Questions about JWT Decoder

Does decoding verify the token signature?
No. Client-side decoding inspects payload and header claims only. Signature verification requires secret keys on your backend authentication server.
Is my JWT token transmitted to a server?
No. Token decoding runs entirely in your local browser JavaScript thread.
Why is my token shown as expired?
Its exp time is in the past compared with your computer's clock. If the clock is wrong, the status will be too.
Can I edit a token here?
No. Changing the payload would invalidate the signature, so editing is not offered.
Which algorithms are supported?
Any. Decoding only reads the header and payload, so tokens signed with HS256, RS256, ES256, or any other algorithm can be inspected.

Comments

Questions, ideas, or a bug in JWT Decoder? Let us know.