JWT decoder
Paste a token to read its header and payload, see when it expires, and optionally check its signature with a secret or public key.
Your data never leaves your browser
Paste API responses and tokens safely: nothing is sent anywhere.
JWT token
Decoding is not verification
Anyone can read a JWT. Decoding shows what it says, not that it is genuine. Check the signature below, or on your server, before you trust it. The token never leaves your browser.
Next, try one of these tools
How to use
- 1Paste your JWT. A “Bearer ” prefix is fine.
- 2Read the header, the payload and the claims in plain language.
- 3To verify, paste the secret (HS*) or the public key (RS*, ES*) and press Verify.
- 4Remember that decoding alone does not prove a token is genuine.
Common uses
Debugging a login
See what claims your identity provider really put in the token and when it expires.
Why am I getting 401?
Check for an expired token, a wrong audience or a missing role.
Testing signatures
Confirm that a token was signed with the secret or key you expect.
Learning JWT
Take apart a sample token to see how header, payload and signature fit together.
Tips and limits
- A valid-looking token that fails verification is the normal sign of a wrong key, a wrong algorithm or a modified token.
- exp, nbf and iat are Unix timestamps in seconds. A date in 1970 usually means a value in milliseconds was treated as seconds.
- Tokens with five parts are encrypted (JWE) and cannot be decoded without the decryption key.
- A token with alg set to none carries no signature. Servers should reject it.
Read a JWT, then decide whether to trust it
A JSON Web Token is three Base64URL parts joined by dots. Paste one and the decoder shows the header and the payload as formatted JSON, the signing algorithm, and the standard claims in plain language: who issued it (iss), who it is about (sub), who it is for (aud), and the times exp, nbf and iat as dates in your own time zone, with how long until it expires or how long ago it did. A badge tells you at a glance whether the token is currently valid, expired or not active yet. A “Bearer ” prefix copied from a header is removed for you, and Arabic or emoji inside claims display correctly.
Decoding is not verification. Anyone can read a token, so the useful question is whether the signature is genuine. Paste the secret for HS256, HS384 and HS512, or the public key as PEM or JWK for RS256, RS384, RS512, ES256, ES384 and ES512, and the page checks the signature with your browser’s Web Crypto and reports valid, invalid or not checked. Read what a JWT is for the full picture. For the pieces around a token, use the Base64 tool for raw segments, the JSON formatter for large payloads, and the hash generator to reproduce an HMAC.
Step-by-step guides
Frequently asked questions
How do I decode a JWT?
Paste the token into the box. The header, payload and claims appear immediately, with dates shown in your time zone.
Is it safe to paste my token here?
The decoder runs entirely in your browser and sends the token nowhere. Still, treat live production tokens as secrets and prefer test tokens.
Does decoding prove the token is valid?
No. It only reads the contents. Use the verification box with the correct secret or public key to check the signature.
Which signature algorithms can it verify?
HS256, HS384, HS512 with a secret, and RS256, RS384, RS512, ES256, ES384, ES512 with a public key in PEM or JWK form.
How do I read the exp claim?
The tool converts it to your local date and says whether it has passed. exp is a Unix time in seconds.