JWT Decoder
Paste a JWT to inspect its header, claims and expiry — decoded locally, nothing is verified or sent anywhere.
What this tool does — and does not do
A JWT is three Base64url-encoded segments joined by dots: header, payload and signature. This
decoder reveals the header (algorithm, type) and payload (claims), and translates standard
timestamp claims — exp, iat, nbf — into readable dates with an
expiry verdict. It does not verify the signature: verification needs the secret or
public key, and trusting an unverified token's contents is unsafe. Never make authorization
decisions based on a decoded-but-unverified token.
FAQ
Is it safe to paste my JWT here?
Yes — decoding happens entirely in your browser and the token is never stored or transmitted. Still, avoid pasting production tokens anywhere as a general habit.
Which algorithms can it decode?
All of them — decoding is algorithm-independent. Signature verification (HS256, RS256, ES256, etc.) is a planned separate tool.
What does "exp" mean?
exp is the expiration time in Unix seconds. After it passes, the token should be rejected by the server (assuming it checks).
JWT Decoder — FAQ
Is JWT Decoder free to use?
Yes. It is completely free, with no signup, no installation and no usage limits.
Is my data uploaded to a server?
No. The tool runs entirely in your browser — the data you paste or upload never leaves your device.
Does it work on mobile devices?
Yes. It works in any modern desktop or mobile browser, with nothing to install.