JWT Decoder
See what is inside a JSON Web Token and whether it has expired.
How to use the JWT Decoder
- Paste a JWT into the left panel. You can include the "Bearer " prefix from an Authorization header.
- The header and payload appear as formatted JSON on the right.
- Check the dates section to see when the token was issued, when it becomes valid and when it expires.
- Copy the decoded output, or switch to payload-only to grab just the claims.
Examples
About this tool
A JSON Web Token (JWT) is three Base64url-encoded parts joined by dots: a header that names the signing algorithm, a payload of claims such as the user ID, roles and expiry time, and a signature. The first two parts are not encrypted, only encoded, so anyone holding the token can read them. This decoder does exactly that and lays the claims out as readable JSON.
Time claims are stored as Unix seconds, which are hard to read at a glance. The tool translates iat (issued at), nbf (not before) and exp (expires) into calendar dates, shows how long ago or how far away each one is, and tells you whether the token is currently expired or not yet valid. That makes it quick to debug "401 Unauthorized" errors caused by clock skew or short-lived tokens.
Important: decoding is not verification. This tool does not check the signature, so it cannot tell you whether a token is genuine or has been tampered with. Always verify tokens on your server with the correct secret or public key.
Frequently asked questions
Is it safe to paste a real token here?
Decoding happens entirely in your browser and the token is never sent anywhere. Still, treat live tokens like passwords: prefer expired or test tokens when sharing your screen.
Does this verify the signature?
No. It only decodes the header and payload. Verifying requires the signing secret or public key and should be done by your backend or auth library.
Why does it say the token is expired?
The exp claim is earlier than your device's current time. If that seems wrong, check your computer clock; a skew of a few minutes is a common cause of authentication errors.
Can it decode encrypted JWTs (JWE)?
No. A JWE has five parts and its payload is encrypted, so it cannot be read without the key. This tool handles signed tokens (JWS) with three parts.