JWT Decoder
Decode JWT header and payload locally, read exp and iat as human dates. Signature not verified.
Header
—
Payload
—
Signature(not verified — decode only)
Warning: decoding does not verify a token. Never trust payload claims from an untrusted source without signature verification on your server.
How to use it
- Paste a JWT (the
eyJ…string with three dot-separated parts). - The header and payload are decoded and pretty-printed instantly.
- Registered claims such as
expandiatare shown as human-readable dates with an expiry warning when a token has lapsed.
Common use cases
- Debugging auth flows — see exactly which claims an access token carries and when it expires.
- Checking refresh-token windows — confirm the
expof a refresh token against the clock. - Reading third-party tokens — decode a token from a service you integrate with so you know what it contains before you trust its claims.
FAQ
Q: Does this tool verify the signature? A: No, and it says so clearly. Decoding shows the claims, but anyone can forge unsigned claims. Signature verification must happen on your server with the correct secret or public key.
Q: Is the token safe to paste? A: This page never transmits anything, but a JWT in the wild may already be readable by anyone who holds it. Treat paste-sensitive tokens as you would any credential.
Q: Why is my token "invalid"? A: Check that it is a complete JWT with exactly three parts. Refresh tokens in opaque formats (like random hex) are not JWTs and cannot be decoded.
Used in these workflows
Your data stays on this device
JWT Decoder runs 100% locally. Everything you paste or drop is processed by your own browser and never transmitted. Nothing is stored on our servers — close the tab and it is gone.
Nothing you type is sent to a server, logged, or used for analytics. The page works even with your network disconnected after first load.