๐ JWT Decoder
Decode a JWT (JSON Web Token) to inspect its header and payload contents. It also flags whether the token has expired. Useful for checking a token's contents during API development or debugging an authentication issue.
How to use
- Paste a JWT string into the "JWT Token" field.
- The header and payload are decoded and displayed.
- See whether the token is still valid or expired, based on its exp claim.
How the calculation works
A JWT (JSON Web Token, RFC 7519) is three parts joined by dots: header.payload.signature. The header names the signing algorithm (such as HS256); the payload carries "claims" such as the user ID and expiry time, as JSON. The header and payload are merely encoded in URL-safe Base64URL โ they are not encrypted. This tool converts Base64URL's "-" and "_" back to Base64's "+" and "/", restores the omitted padding (=), decodes, and shows the resulting JSON. Among the standard claims, exp (expiry), iat (issued at) and nbf (not before) are Unix times: seconds since 1 January 1970 UTC. The tool compares exp with the current time to show whether the token has expired. It does not verify the signature, so it cannot tell you the contents have not been tampered with.
Worked example
Decoding this token (signature omitted) eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0IiwibmFtZSI6IlRhcm8iLCJpYXQiOjE3NTgxNjgwMDAsImV4cCI6MTc1ODE3MTYwMH0 Header: {"alg": "HS256", "typ": "JWT"} Payload: {"sub": "1234", "name": "Taro", "iat": 1758168000, "exp": 1758171600} iat is 2025-09-18 04:00:00 UTC and exp an hour later, 05:00:00 UTC. That time has passed, so the token shows as expired.
Things to be aware of
- The signature is not verified. Checking for tampering requires validation with the issuer's key.
- Anyone can decode the payload. Never put passwords or other secrets in a JWT.
- Expiry is judged against your device's clock; if the clock is off, so is the result.
- Encrypted JWTs (JWE, which have five parts) are not supported.
FAQ
Does it verify the signature?
No โ this tool only decodes and displays the header and payload; it does not verify the signature, so no secret key is needed and nothing unsafe happens.
Can it tell me if a token has expired?
Yes โ it checks the exp (expiration) claim in the payload and shows whether the token is expired.
Is my pasted token sent to a server?
No, decoding happens entirely in your browser and nothing is sent externally, so you can safely inspect tokens that contain sensitive claims.
Can I see what standard claims like sub or iat mean?
The decoded payload is shown as plain JSON, so you can see the raw values of standard claims like sub, iat, and exp directly.
What happens if I paste a malformed token?
If the input isn't a valid JWT (header.payload.signature separated by dots), a parse error is shown.