JWT Decoder — Inspect JSON Web Tokens
Decode JWT header and payload and check expiry (no signature verification)
Runs in your browser · nothing is uploaded
This tool only decodes the token. It does NOT verify the signature, so being readable does not mean the token is valid or trustworthy. Nothing leaves your browser.
What it is
A JWT (JSON Web Token) carries claims such as who a user is. It has three dot-separated parts: header, payload and signature. The first two are base64url-encoded JSON, so anyone can read them. This tool unpacks the token and shows the content neatly, but it does not check the signature.
How to use
- Paste the token into the input. A leading
Bearerand any line breaks are ignored. - The header and payload appear as indented JSON, each with its own copy button.
- If the payload has exp, iat or nbf, they are shown as readable dates with the time left or passed (“in 3 hours”, “2 days ago”), and the expiry status is noted.
- If the token is malformed, the error tells you which part is wrong. A five-part encrypted token (JWE) is reported as unreadable without its key.
How it works
- Structure follows RFC 7519 (JWT) and RFC 7515 (JWS): exactly three parts separated by dots.
- Each part is decoded from base64url as in RFC 4648 (
-and_, padding optional) and read as UTF-8. - The header and payload must be JSON objects; an array or a string is reported as an error.
- exp, iat and nbf are interpreted as seconds only when they are numbers, then shown in your locale’s format and in ISO 8601 (UTC).
- The expiry status only compares the current time with exp and nbf. The signature is not verified, so tokens with alg none or a wrong signature decode just the same.
Examples
| Part | Content |
|---|---|
| Token start | eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9 |
| header | {"alg": "HS256", "typ": "JWT"} |
| payload | {"sub": "1234567890", "name": "John Doe", "iat": 1516239022} |
| iat | 2018-01-18T01:30:22Z |
That token is the usual practice sample found in JWT introductions. A token whose payload contains {"name": "홍길동"} also decodes without garbling.
FAQ
Does this tool verify the JWT signature?
No, it only decodes. Being able to read a token does not mean it is genuine or valid. Trust has to be decided by verifying the signature with the secret or public key on your server.
Is it safe to paste a token here?
Decoding happens only in your browser and the token is not transmitted. Even so, avoid pasting live production tokens into shared screens or documents.
Will non-English text in the payload display correctly?
Yes. A JWT is base64url-encoded UTF-8 JSON, and this tool decodes it as UTF-8, so names in Korean, Chinese and similar scripts, or emoji, show up intact.
What kind of time is the exp value?
A NumericDate, meaning seconds since 1 January 1970 UTC. The tool shows it in your browser's language and time zone, together with the UTC ISO 8601 form.