JWT decoder
Decode a JSON Web Token and read its header, claims and expiry.
The three parts
A JWT is three Base64URL segments joined by dots. The header names the signing algorithm. The payload carries the claims — who the token is about, who issued it, when it expires. The signature proves the first two have not been altered.
The essential thing to understand: the payload is encoded, not encrypted. Anyone holding the token can read every claim in it, exactly as this page does. Putting anything confidential in a JWT payload is putting it in public.
Expiry, decoded
The exp, iat and nbf claims are Unix timestamps — unreadable at a glance and the usual reason for debugging a token at all. They are shown here as dates, with expired tokens flagged. "Works on my machine but not in production" is very often a clock difference of a few seconds against a token that expires in sixty.
The signature is not verified here, deliberately
Verifying it requires the signing secret or public key. A page that asked you to paste your signing secret would be asking for the one thing that must never leave your server — and any site that does ask should be treated as hostile.
So this decodes and displays. Verification belongs in your application, using a library that also checks the algorithm — the classic JWT attack is switching alg to none and hoping the verifier believes it.
Nothing is transmitted
Decoding happens entirely in your browser. Tokens are credentials: pasting one into a site that posts it to a server hands over a working session. Nothing here leaves the page.
Common questions
Is a JWT encrypted?
No. The payload is Base64-encoded and readable by anyone holding the token. Never put secrets in it.
Why is the signature not verified?
That needs your signing secret, which must never be pasted into a web page. Verify in your application instead.
What do exp, iat and nbf mean?
Expiry, issued-at and not-valid-before, all as Unix timestamps. They are shown here as readable dates.
Is my token sent anywhere?
No. A token is a credential — decoding happens entirely in your browser.
Why does my token say invalid?
A JWT has exactly three dot-separated parts. Truncation when copying is the usual cause.