JWT Decoder
Decode a JSON Web Token and inspect its header, payload, and claim timestamps without verifying the signature.
How it works
- 1
Paste a JWT — the three-part dot-separated token — into the input field.
- 2
The tool splits the token and decodes the header and payload from base64url.
- 3
Claim timestamps like iat, exp, and nbf are shown as human-readable UTC strings.
Questions
Is the signature verified?
No. This tool only decodes the header and payload, which are base64url-encoded and not secret. Verification needs the signing key and is beyond the scope of inspection tools.
What does the expired badge mean?
The token's exp claim is a Unix timestamp. If that time is in the past, the token is considered expired by any server that checks it.
Does my token leave the browser?
No. Decoding runs entirely in your browser using the Web Crypto base64url API. Your token is never sent to any server.
Why does my token have no exp or iat?
Those claims are optional. A token without exp never expires by its own terms; one without iat simply lacks an issuance timestamp.
More developer tools
JSON Formatter
Paste compact or messy JSON and get it back neatly indented with your chosen spacing.
JSON Minifier
Remove all whitespace and line breaks from a JSON document to shrink it as small as possible.
JSON Validator
Check whether a JSON string is well-formed, and see the exact line and column of any syntax error.
JSON Beautifier
Reformat JSON with sorted keys and readable indentation for easier reading and diffing.
JSON Tree Viewer
Explore a JSON document as an interactive collapsible tree — expand and collapse any node.
XML Formatter
Pretty-print XML with configurable indentation, preserving attributes, comments, and tag order.
XML Validator
Check XML for well-formedness and report every error with its line and column number.
YAML Formatter
Normalize and re-indent YAML, or convert it to JSON, with a configurable indent width.