JWT Decoder
Paste a JWT to decode its header and payload as readable JSON, with issued-at and expiration dates highlighted. This tool decodes only — it never verifies a signature.
Everything you enter is processed in your browser and isn't sent to our servers.
How to use jwt decoder
- 1Paste a JWT into the input box.
- 2View the decoded, pretty-printed header and payload.
- 3Check issued-at, expiration and not-before dates if the token includes them.
- 4Copy either the header or payload as JSON.
About this tool
A JSON Web Token (JWT) is made of three Base64URL-encoded parts separated by dots: a header describing the token, a payload containing its claims, and a signature used to verify authenticity. The header and payload are plain JSON once decoded — no secret is required to read them.
This tool decodes those first two parts so you can inspect a token's contents during development or debugging. Because decoding doesn't require the signing key, it's only ever safe to treat this as a way to read a token, never as proof that the token is genuine.
Standard time-based claims — iat (issued at), exp (expiration) and nbf (not before) — are detected automatically and shown as human-readable dates when present, since they're stored internally as raw Unix timestamps.
Frequently asked questions
No, and it's important to understand why: verifying a JWT requires checking its signature against the issuer's secret or public key, which this tool never has access to. It only decodes the readable header and payload — it never confirms the token hasn't been tampered with or forged.