JWT Decoder

Read the header and claims of a JSON Web Token, see the algorithm, subject, issued time, and expiry, and check whether it has already expired.

A JWT decoder splits a JSON Web Token into its three parts and decodes the header and claims. Decoding needs no secret, which means it verifies nothing, so a readable token is not proof that a signature is valid.

Paste a token above.

Header


                

Payload


                
Issued at
Expires at
Status
Signature

Questions about jwt decoder

Does decoding verify the signature?
No. Verification needs the secret or the public key. Anything can craft a token that decodes cleanly.
What do the expiry claims mean?
The exp claim is the moment the token stops being valid, iat when it was issued, and nbf when it becomes valid. All three are Unix seconds.
Is it safe to paste a token here?
Nothing is uploaded, and a token is only readable by whoever holds it. Still, treat one as a credential and do not paste a live production token.