About this jwt decoder
A JSON Web Token (JWT) is a compact string used to carry identity and permission claims between systems, typically after you sign in. It has three dot-separated parts: a header, a payload and a signature. This decoder reads the first two so you can see what a token contains and when it expires.
Decoding is done entirely in your browser and the token is not uploaded. This tool does not verify signatures, and it should not be used to decide whether a token can be trusted.
How to use it
- Paste the token into the box. A leading “Bearer ” prefix is removed automatically.
- Read the decoded header (algorithm and type) and the payload (claims).
- Check the claims table for issued-at, not-before and expiry times, and whether the token has expired.
- Copy the header or payload JSON if you need it for debugging.
Anatomy of a JWT
A JWT looks like xxxxx.yyyyy.zzzzz. The first part is the header, a small JSON object that names the signing algorithm (such as HS256 or RS256) and the token type. The second is the payload, a JSON object of claims. The third is the signature, which lets a server confirm that the header and payload were not altered. Each part is encoded with Base64URL, which is why you can read the first two without any key.
JWTs are defined by RFC 7519. Because the content is only encoded and not encrypted (unless it is a separate encrypted token type), anything in the payload is visible to anyone who holds the token. Never put secrets or sensitive personal data in a JWT payload.
Registered claims explained
The standard defines several common claims. iss (issuer) says who created the token; sub (subject) identifies the user or entity it is about; aud (audience) names the recipient it is meant for; exp (expiration time) is when it stops being valid; nbf (not before) is when it starts being valid; iat (issued at) is when it was created; and jti is a unique token identifier. The time claims are Unix timestamps in seconds, which this tool converts into readable UTC times and compares with your current time.
Applications also add their own claims, such as roles, scopes, tenant IDs or email addresses. Those appear in the payload JSON exactly as issued.
Decoding is not verifying
Reading a token and trusting it are very different. A forged token can look perfectly normal when decoded. To trust a JWT, a server must verify the signature with the correct key, check that the algorithm is one it expects, and validate exp, nbf, iss and aud. Known attacks include accepting the “none” algorithm or confusing symmetric and asymmetric algorithms, which is why verification belongs in well-tested libraries on the server and never in client-side inspection tools.
Treat real tokens as credentials. Although this tool processes the token locally, a live access token pasted into any web page could be exposed through browser extensions, screen sharing or clipboard managers. When possible, use expired or test tokens for debugging.
Frequently asked questions
Does this tool verify the signature?
No. It only decodes the header and payload. Signature verification requires the signing key and should be done on your server with a trusted library.
Is my token sent to a server?
No. The token is decoded in your browser and not transmitted anywhere.
Why can anyone read my JWT payload?
Because JWT parts are Base64URL-encoded, not encrypted. Do not store secrets in a payload.
What do exp, iat and nbf mean?
exp is when the token expires, iat is when it was issued, and nbf is the earliest time it is valid. All are Unix timestamps in seconds.
What does “EXPIRED” mean in the results?
The exp claim is earlier than the current time on your device. The server will normally reject such a token.
Why do I get “invalid” for my token?
It may not have exactly three dot-separated parts, may be truncated, or may be an opaque token (not a JWT) or an encrypted JWE, which cannot be read this way.
Related tools
- Base64 Encoder & DecoderEncode text to Base64 or decode Base64 back to text, with full Unicode and URL-safe support.
- Unix Timestamp ConverterConvert epoch timestamps to readable dates and dates back to timestamps, in any common unit.
- URL Encoder & DecoderPercent-encode or decode URLs and query strings, and break a URL into its parts.
- Secure Password GeneratorCreate strong random passwords using your browser’s cryptographic random number generator.