ToolDashy

JWT Decoder

Paste a JWT to decode its header and payload as readable JSON, with issued-at and expiration dates highlighted. This tool decodes only — it never verifies a signature.

This only decodes the token's contents — it does not verify the signature. A decoded token here is never proof that it's genuine, unexpired, or safe to trust; verify the signature server-side before relying on it.

Everything you enter is processed in your browser and isn't sent to our servers.

How to use jwt decoder

  1. 1Paste a JWT into the input box.
  2. 2View the decoded, pretty-printed header and payload.
  3. 3Check issued-at, expiration and not-before dates if the token includes them.
  4. 4Copy either the header or payload as JSON.

About this tool

A JSON Web Token (JWT) is made of three Base64URL-encoded parts separated by dots: a header describing the token, a payload containing its claims, and a signature used to verify authenticity. The header and payload are plain JSON once decoded — no secret is required to read them.

This tool decodes those first two parts so you can inspect a token's contents during development or debugging. Because decoding doesn't require the signing key, it's only ever safe to treat this as a way to read a token, never as proof that the token is genuine.

Standard time-based claims — iat (issued at), exp (expiration) and nbf (not before) — are detected automatically and shown as human-readable dates when present, since they're stored internally as raw Unix timestamps.

Frequently asked questions

No, and it's important to understand why: verifying a JWT requires checking its signature against the issuer's secret or public key, which this tool never has access to. It only decodes the readable header and payload — it never confirms the token hasn't been tampered with or forged.

Related tools