JWT Decoder

Paste a JWT to inspect its header, claims and expiry — decoded locally, nothing is verified or sent anywhere.

JWT (three dot-separated Base64url segments)
Header
Payload
Timestamps & status

What this tool does — and does not do

A JWT is three Base64url-encoded segments joined by dots: header, payload and signature. This decoder reveals the header (algorithm, type) and payload (claims), and translates standard timestamp claims — exp, iat, nbf — into readable dates with an expiry verdict. It does not verify the signature: verification needs the secret or public key, and trusting an unverified token's contents is unsafe. Never make authorization decisions based on a decoded-but-unverified token.

FAQ

Is it safe to paste my JWT here?

Yes — decoding happens entirely in your browser and the token is never stored or transmitted. Still, avoid pasting production tokens anywhere as a general habit.

Which algorithms can it decode?

All of them — decoding is algorithm-independent. Signature verification (HS256, RS256, ES256, etc.) is a planned separate tool.

What does "exp" mean?

exp is the expiration time in Unix seconds. After it passes, the token should be rejected by the server (assuming it checks).

JWT Decoder — FAQ

Is JWT Decoder free to use?

Yes. It is completely free, with no signup, no installation and no usage limits.

Is my data uploaded to a server?

No. The tool runs entirely in your browser — the data you paste or upload never leaves your device.

Does it work on mobile devices?

Yes. It works in any modern desktop or mobile browser, with nothing to install.