Skip to content

JWT decoder

Decode a JSON Web Token and read its header, claims and expiry.

Runs in your browser — nothing is sent anywhere.

The three parts

A JWT is three Base64URL segments joined by dots. The header names the signing algorithm. The payload carries the claims — who the token is about, who issued it, when it expires. The signature proves the first two have not been altered.

The essential thing to understand: the payload is encoded, not encrypted. Anyone holding the token can read every claim in it, exactly as this page does. Putting anything confidential in a JWT payload is putting it in public.

Expiry, decoded

The exp, iat and nbf claims are Unix timestamps — unreadable at a glance and the usual reason for debugging a token at all. They are shown here as dates, with expired tokens flagged. "Works on my machine but not in production" is very often a clock difference of a few seconds against a token that expires in sixty.

The signature is not verified here, deliberately

Verifying it requires the signing secret or public key. A page that asked you to paste your signing secret would be asking for the one thing that must never leave your server — and any site that does ask should be treated as hostile.

So this decodes and displays. Verification belongs in your application, using a library that also checks the algorithm — the classic JWT attack is switching alg to none and hoping the verifier believes it.

Nothing is transmitted

Decoding happens entirely in your browser. Tokens are credentials: pasting one into a site that posts it to a server hands over a working session. Nothing here leaves the page.

01

Common questions

Is a JWT encrypted?

No. The payload is Base64-encoded and readable by anyone holding the token. Never put secrets in it.

Why is the signature not verified?

That needs your signing secret, which must never be pasted into a web page. Verify in your application instead.

What do exp, iat and nbf mean?

Expiry, issued-at and not-valid-before, all as Unix timestamps. They are shown here as readable dates.

Is my token sent anywhere?

No. A token is a credential — decoding happens entirely in your browser.

Why does my token say invalid?

A JWT has exactly three dot-separated parts. Truncation when copying is the usual cause.