JWT Decoder

Split a JSON Web Token into header, payload and signature, convert its timestamps to local time, and see at a glance whether it has expired.

JWTJOSEAuth

Token

Waiting for a token.

Header

Payload

Registered claims

Signature

The signature is shown as received. This page does not verify it, because verification needs the secret or public key and would require re-computing an HMAC or an RSA/ECDSA signature.

About this JWT decoder

A JSON Web Token (RFC 7519) is three Base64URL-encoded segments joined by dots: a header, a payload and a signature. This tool splits the token on those dots and Base64URL-decodes the first two, then pretty-prints the JSON inside them so you can read the claims.

The single most important thing to understand is that the payload is not encrypted. Base64URL is a reversible transport encoding, not a cipher, so anyone holding the token can read every claim in it — which is exactly why this decoder can show it to you without any key. Never put secrets, passwords or personal data in a JWT payload, and treat any token you find as already public.

Decoding is not verifying. A token can be decoded perfectly while being forged or expired. Real validation means checking the signature against the issuer's key, then checking exp, nbf, iss and aud server-side. This page helps with the first half of that work only: it shows the timestamps converted to your local time and flags an expired token, but it makes no claim about authenticity.

Related tools

Found a bug, or need a tool that is not here? Email 2273917172@qq.com — a human reads every message.