JWT Decoder

Decode JWT (JSON Web Tokens).

Usage examples

Checking what's inside a login token

Curious what claims (user ID, roles, etc.) your server's JWT access token carries? Paste it in and see the header and payload as readable JSON instantly.

Checking when a token expires

Debugging why users keep getting logged out? The exp claim is shown as a human-readable date and time, with a badge telling you if it's already expired.

Checking the signing algorithm

Not sure if a token is HS256 or RS256? The header's alg value is shown right in the summary panel.

Sharing a decoded token with a teammate

Want a coworker to look at the same token? Click "Copy share link" to copy a link containing the token you're viewing — anyone who opens it sees the same token decoded instantly.

Frequently asked questions

Does this tool verify the signature?

No. Verifying a signature requires the secret (or public) key that only the issuer should know, and typing that into any website is a security risk. This tool only decodes and displays the header and payload — it never checks whether the signature is valid.

How does the share link carry the token?

Clicking "Copy share link" copies a link with ?jwt=<token> appended — so the token itself is exposed right in the URL. Opening that link shows this token instantly (instead of whatever was previously saved) and updates local storage to match. If you share the link over chat or email, the token can end up sitting in that history, so think twice before sharing a link built from a real, valid production token.

Is the token I paste sent to a server?

No. All decoding happens entirely in your browser and is never sent to a server. So you can pick up where you left off on your next visit, the token you type is saved only in your browser's local storage (localStorage) — it's not shared across devices or browsers. Clearing the input also clears what's saved. That said, it's still good practice to avoid pasting real production tokens into random websites.

What are exp, iat, and nbf?

These are common standard JWT claims. iat is when the token was issued, exp is when it expires, and nbf ("not before") means the token isn't valid until that time. They're stored as Unix timestamps (seconds since Jan 1, 1970), which this tool converts into human-readable dates.

I'm getting an invalid format error.

A JWT must have exactly 3 dot-separated parts (header.payload.signature). Check whether stray whitespace got mixed in, or whether the token was copied incompletely.