Skip to content
QuickKit 100% free · no login

Home › Developer Tools › JWT Decoder

JWT Decoder

Runs in your browserFree · no sign-up

Paste a JSON Web Token to see its header, payload and timing claims. The token is decoded in your browser and never uploaded.

Header


  

Payload


  

Signature (raw, not verified)


Advertisement

What is in a JSON Web Token

A JSON Web Token (JWT, pronounced "jot") is a compact string that servers hand to clients to prove who they are. It has three parts separated by dots. The first is the header, a small JSON object naming the signing algorithm and token type. The second is the payload, a JSON object of claims such as the subject (sub), the issuer (iss), the audience (aud), when it was issued (iat), when it starts being valid (nbf) and when it expires (exp). The third is the signature. The first two parts are only Base64URL-encoded, which is why anyone holding the token can read them, as this tool does.

What the decoder shows

The tool splits the token, converts the first two parts from Base64URL into text, parses them as JSON and prints them formatted. For the standard time claims, which are stored as seconds since 1 January 1970, it converts the numbers to readable UTC dates and tells you whether the token has already expired compared with your device clock. Custom claims, such as roles or tenant IDs, are shown exactly as they appear.

Decoding is not verifying

This is the most important point. Reading a token does not prove it is genuine. Only the server holding the secret key (or the public key for RSA and ECDSA algorithms) can verify the signature, and this tool does not attempt to. Never trust claims in a token you have not verified. Likewise, because payloads are readable, you should not place secrets such as passwords in a JWT.

Debugging tips

  • If you copied the value from an Authorization header, the "Bearer " prefix is removed automatically.
  • An "alg": "none" header is a warning sign. Properly configured servers reject unsigned tokens.
  • Clock differences between servers can make a fresh token look "not yet valid" or expired by a few seconds.
  • Encrypted tokens (JWE) have five parts and cannot be read without the key. This tool will report that it cannot decode them.

Privacy

Decoding is done locally in the page. Even so, treat live tokens as passwords: a valid access token lets someone act as you until it expires. Prefer expired or test tokens when you can.

Frequently asked questions

What is a JWT?

A JSON Web Token is a signed string with a header, a payload of claims and a signature, used to carry identity or authorisation information between systems.

Does this tool verify the signature?

No. It only decodes the readable parts. Verification needs the secret or public key and must be done on your server.

Is it safe to paste my token here?

The token is decoded in your browser and not sent anywhere, but live tokens are credentials. Use test or expired tokens where possible.

What do iat, nbf and exp mean?

Issued-at, not-before and expiration times, expressed in seconds since 1970-01-01 UTC. The tool converts them into dates.

Why can’t it decode my token?

It may be incomplete, encrypted (JWE) or not a JWT at all. A JWT has exactly three dot-separated parts.

More free tools