JWT Decoder

Paste a JWT to decode and inspect its header, payload, and signature. Check expiration status.

Token

All processing happens entirely in your browser. No data is sent to any server.

What the JWT decoder does

A JSON Web Token packs three Base64URL-encoded parts — header, payload, and signature — separated by dots. This decoder splits the token, decodes the header and payload to readable JSON, and surfaces the standard claims (issuer, subject, audience, and the exp expiry) so you can see exactly what a token asserts. It runs entirely in your browser — the token never leaves your machine.

How to decode a JWT

  1. Paste the token (the eyJ… string) into the box above.
  2. Read the decoded header (algorithm + type) and payload (claims).
  3. Check the expiration status — the tool flags whether exp is in the past.

Decoding is not verifying

Anyone can decode a JWT — the payload is only encoded, not encrypted. Decoding shows what a token claims; it does not prove the token is authentic. Verification means checking the signature against the issuer's secret or public key, which happens on your server. Never trust a decoded payload as proof of identity without verifying the signature first.

Frequently asked questions

Is it safe to paste a JWT here?

Decoding runs client-side in your browser; nothing is sent to a server. Still, treat production tokens as secrets — avoid pasting live tokens into any online tool you don't control.

Why can I read the payload without a key?

JWT payloads are Base64URL-encoded, not encrypted. The signature protects against tampering, not reading — so never store sensitive data in a JWT payload.

What does "expired" mean?

The exp claim is a Unix timestamp; if it is earlier than now, the token has expired and a correct server will reject it.

SharePost

More tools like this