JWT Decoder
Read the header and claims of a JSON Web Token, see the algorithm, subject, issued time, and expiry, and check whether it has already expired.
How to use
- Paste the token.
- Read the algorithm, claims, and expiry.
- Check the expiry line before trusting a token in a test.
A JWT decoder splits a JSON Web Token into its three parts and decodes the header and claims. Decoding needs no secret, which means it verifies nothing, so a readable token is not proof that a signature is valid.
Header
Payload
- Issued at
- Expires at
- Status
- Signature
Questions about jwt decoder
- Does decoding verify the signature?
- No. Verification needs the secret or the public key. Anything can craft a token that decodes cleanly.
- What do the expiry claims mean?
- The exp claim is the moment the token stops being valid, iat when it was issued, and nbf when it becomes valid. All three are Unix seconds.
- Is it safe to paste a token here?
- Nothing is uploaded, and a token is only readable by whoever holds it. Still, treat one as a credential and do not paste a live production token.
Related tools
- JWT Generator Create a signed JSON Web Token in the browser with HS256, HS384, or HS512, adding issued-a...
- Timestamp Converter Convert a date and time between ISO 8601, UTC, local time, and Unix seconds and millisecon...
- Base64 Decoder Decode a Base64 string back to text, with UTF-8 validation and a hex dump when the decoded...