Developer · Free
JWT Decoder
Decode a JSON Web Token to read its header, payload and expiry. Runs entirely in your browser, so your tokens are never sent to a server.
About this tool
A JWT is three Base64url-encoded parts separated by dots: a header (the signing algorithm), a payload (the claims — who the user is, what they may do, when the token expires) and a signature. Paste a token, with or without the "Bearer " prefix, to see the header and payload as formatted JSON.
The iat (issued at), nbf (not before) and exp (expires) claims are converted to readable dates, and the tool tells you whether the token has already expired according to your device's clock.
This is a decoder, not a validator: it does not check the signature, which requires the issuer's secret or public key. Never trust a token's contents on the server without verifying it. Because decoding happens locally, it is safe to paste real tokens here.
More free tools: see the whole hub → · Looking for paid software instead? Browse every directory →
Last updated · How we research and update