JWT Decoder

Paste a JSON Web Token to read its header and claims, see when it expires, and optionally verify its signature. Everything happens in your browser; the token is never sent or stored.

Encoded token
Verify signature (optional)

What's inside a JWT

A JSON Web Token is three base64url strings joined by dots:

header.payload.signature

Decoding only reverses the base64url step, which is why you can read any token without a key. That also means a JWT payload is not private: don't put passwords, card numbers or other secrets in it.

Checking expiry

The times in a JWT are Unix timestamps in seconds. The decoder turns exp, iat and nbf into readable dates, in UTC and in your local time zone, and shows at the top whether the token is still valid. A common bug is writing milliseconds instead of seconds (a 13-digit number); the decoder warns you when it sees that.

Verifying the signature

Paste the key under Verify signature:

Verification uses your browser's built-in Web Crypto API. A green result means the token was signed with that key and hasn't been changed since. Your server still has to check exp, aud and iss itself.

Warnings the decoder shows

Frequently asked questions

Is it safe to paste a real token here?

The token is decoded and verified inside your browser and is never sent to our server or saved. Still, treat production tokens like passwords: anyone who has a valid token can use it until it expires.

Why can I read the payload without the secret?

A standard JWT is signed, not encrypted. The header and payload are only base64url-encoded, so anyone can read them. The signature stops people from changing the contents, not from reading them. Never put passwords or other secrets in a JWT payload.

Which algorithms can be verified?

HS256, HS384 and HS512 with a shared secret; RS256, RS384, RS512, PS256, PS384 and PS512 with an RSA public key; and ES256, ES384 and ES512 with an EC public key. Keys can be pasted as PEM (BEGIN PUBLIC KEY) or as a JWK or JWKS.

What do exp, iat and nbf mean?

They are times in seconds since 1 January 1970 (UTC). exp is when the token expires, iat is when it was issued and nbf is the time before which it must not be accepted. The decoder shows each one as a date and as a relative time such as "in 45 minutes".