JWT Decoder

    Decode a JWT's header and payload instantly, with expiry and issued-at times shown as real dates. Decode only, no signature verification.

    Runs in your browser. Nothing is uploaded.No signup requiredBuilt byDATAMETA LAB

    JWT

    How to use this tool

    1. Paste a JWT (the three dot-separated parts) into the box.
    2. The header and payload decode instantly as formatted JSON.
    3. Standard time claims, exp, iat and nbf, show as human-readable dates alongside their raw numbers, and expiry shows a live valid/expired status.
    4. Copy the header or payload JSON with the buttons beside each.

    About this tool

    A JSON Web Token is three base64url-encoded parts separated by dots: a header describing the signing algorithm, a payload of claims, and a signature. This tool decodes the header and payload back into readable JSON and leaves the signature as-is, since decoding is all it does. Decode only, deliberately. Verifying a JWT's signature needs the secret or public key it was signed with, and a page that invites you to paste a signing secret into a browser tool is bad advice regardless of where the JavaScript actually runs, this one included. If you need to verify a token, do it server-side with the key your own service holds. Time claims get special treatment because they are the field people actually need translated: exp, iat and nbf are Unix timestamps, seconds since 1 January 1970, which are useless to read at a glance. Each one is shown next to its human date, and the expiry claim additionally shows a live valid or expired status so you can tell at a glance whether the token you are looking at has already lapsed. Because decoding a live, valid session token is a routine debugging task, and because those tokens are exactly the kind of thing you should not be pasting into a hosted service, everything here runs locally in your browser. Nothing you paste is transmitted, logged or stored.

    Frequently asked questions

    How do I decode a JWT?

    Paste the full token into the box. It splits itself into header, payload and signature; the header and payload decode automatically into formatted JSON as soon as the token is complete.

    Can this verify whether a JWT's signature is valid?

    No, and deliberately so. Verifying a signature requires the secret or public key the token was signed with, and a web page asking you to paste a signing secret into it is a bad idea no matter whose page it is or where the code runs. This tool decodes and displays the header and payload only; verify signatures in your own backend, where the key already lives.

    What do exp, iat and nbf mean?

    They are standard JWT time claims stored as Unix timestamps (seconds since 1 January 1970): exp is when the token expires, iat is when it was issued, and nbf is 'not before', the earliest time it becomes valid. This tool converts each to a readable date next to the raw number, and shows a live valid or expired status based on exp.

    Why did decoding fail?

    A JWT is exactly three dot-separated parts. If a character was dropped when the token was copied, or it's been truncated, wrapped, or isn't a JWT at all, decoding will fail; check the token is complete and unmodified.

    Is my token sent anywhere?

    No. Everything runs as JavaScript in your own browser, and nothing you paste is transmitted, logged or stored. That matters here specifically, since the tokens people decode are very often live session tokens from a real, running application.