JWT Decoder
Paste a JSON Web Token to read its header and payload, see when it expires and verify its signature — entirely on your device.
- Token stays local
- Expiry check
- Signature check
- Instant
Decoded on your device. The token is not sent anywhere and is not saved — reloading the page clears it.
Header
Payload
Claims explained
| Claim | Value | Meaning |
|---|
Verify the signature
Paste a PEM public key (-----BEGIN PUBLIC KEY-----), a JWK or a JWKS. Never paste a private key into any website.
How to decode a JWT
Paste and read.
- 1
Paste the token
With or without the “Bearer” prefix. The three parts are colored so you can see where each begins.
- 2
Read header and payload
Both are shown as formatted JSON. Time claims are translated into dates and every standard claim is explained.
- 3
Verify the signature (optional)
Enter the shared secret or paste the public key to check whether the token is authentic and unchanged.
A decoder you can use with real tokens
Because a production token is a password.
Decoded on your device
The token is processed by JavaScript in your browser. It is not sent to us, not logged and not stored between visits.
Expiry at a glance
A badge shows whether the token is still valid, already expired or not yet valid — with the time left.
Claims explained
iss, sub, aud, exp, nbf, iat, jti and common OpenID claims are described next to their values.
Real signature verification
HMAC, RSA, RSA-PSS, ECDSA and Ed25519 signatures are checked with the Web Crypto API.
PEM, JWK or JWKS
Paste the key in whichever form your identity provider publishes; the matching key of a JWKS is found by its kid.
Warnings that matter
Unsigned tokens (alg: none) and encrypted tokens (JWE) are recognized and explained instead of failing silently.
Instant results
The output updates while you type. There is no button to wait for and no page reload.
Free, no sign-up
No account, no limits, no watermark — on a phone, tablet or computer.
How a JSON Web Token is built
A JWT consists of three Base64URL-encoded parts separated by dots: header.payload.signature. The header names the signing algorithm, the payload carries the claims — statements such as who the user is and until when the token is valid — and the signature proves that header and payload have not been altered since the issuer signed them.
Important: the payload is encoded, not encrypted. Anyone who holds the token can read it, exactly as this tool does, without any key. Never put passwords or other secrets into a JWT, and treat tokens like passwords: whoever has a valid one can act as its user until it expires.
Decoding is not the same as verifying. A server must always check the signature with the expected algorithm, then exp, nbf, the issuer and the audience before trusting a single claim. Tokens with alg: none are unsigned and must be rejected. HMAC algorithms (HS256) use one shared secret for signing and verifying; RSA and ECDSA algorithms (RS256, ES256) sign with a private key and verify with a public one.
Registered claims
| Claim | Name | Meaning |
|---|---|---|
| iss | Issuer | Who created and signed the token |
| sub | Subject | Whom the token is about — usually a user ID |
| aud | Audience | The API or application the token is intended for |
| exp | Expiration time | Unix time after which the token must be rejected |
| nbf | Not before | Unix time before which the token is not valid |
| iat | Issued at | Unix time at which the token was created |
Tips
- Convert an
exporiatvalue by hand with the Timestamp Converter. - Decode a single token part or a Base64URL value with the Base64 Encoder.
- Pretty-print or validate a large payload with the JSON Formatter.
- Keep access tokens short-lived (minutes, not days) and rotate signing keys; publish the public keys as a JWKS so clients can follow the rotation.
Frequently asked questions
Can’t find your answer? Contact us — we reply quickly.
Is it safe to paste my token here?
The token is decoded by code running in your browser and is never transmitted to our server or stored. That said, a production token is a credential: prefer test tokens where you can, and never paste tokens into tools that send them to a server.
Can a JWT be decoded without the secret?
Yes. Header and payload are only Base64URL-encoded, so anyone can read them. The secret or key is needed solely to create or verify the signature.
How do I verify the signature?
For HS256/384/512 enter the shared secret. For RS, PS, ES and EdDSA tokens paste the issuer’s public key as PEM, JWK or JWKS. The result says whether the signature matches.
What does “alg: none” mean?
The token carries no signature at all, so anyone can forge it. Libraries must reject such tokens unless they are explicitly expected, and this tool flags them.
Why is my token shown as expired?
The exp claim holds a Unix timestamp in seconds. If that moment is in the past on your device’s clock, the token is expired. A wrong system clock gives a wrong verdict.
What is the difference between JWT, JWS and JWE?
JWT is the claims format. A JWS is a signed token with three parts — what people usually mean by “JWT”. A JWE is an encrypted token with five parts whose content cannot be read without the decryption key.
More free developer tools
Encode, format, test, convert and generate — small tools that run in your browser and keep your data on your device.