JWT Decoder

Paste a JWT to see its header, claims and expiry time.

Decoding only: the signature is not verified. The token never leaves your browser, but avoid pasting live production tokens anywhere.

JWT structure

A JWT has three base64url parts separated by dots: header (algorithm), payload (claims such as sub, exp and iat) and signature. Anyone can decode the first two, which is why JWTs must never contain secrets.

Common claims

  • exp: expiry time (seconds since 1970, shown here as a date).
  • iat: issued-at time.
  • sub: the user or subject ID.
  • aud / iss: intended audience and issuer.

Frequently asked questions

Does this verify the signature?

No. It only decodes. Signature verification needs the secret or public key and should happen on your server.

Is it safe to paste my token?

Decoding runs locally and nothing is sent. Still, treat live tokens like passwords and prefer test tokens.

Why is my token 'invalid'?

It may be cut off, include 'Bearer ', or not be a JWT at all. Paste only the token itself.

More text and developer tools

See all text and developer tools โ†’