JWT Decoder

Read the header and claims of a JSON Web Token.

Free. Runs in your browser: nothing you enter or open is uploaded.

Do not paste live production tokens into any website. A valid token is a key to an account until it expires. This page decodes in your browser and sends nothing, but the safe habit is to test with expired or development tokens.

Paste a token to read it.

How to use it

  1. Paste a JWT. A leading Bearer is removed for you.
  2. Read the decoded header and payload, and the claims table with dates in your time zone and UTC.
  3. Check the status line to see whether the token has expired or is not valid yet.

Questions

Is a JWT encrypted?

Usually not. A standard signed JWT is only Base64URL encoded, so anyone holding it can read the payload, as this tool shows. Never put secrets in a JWT payload.

Does this tool verify the signature?

No, on purpose. Verifying needs the signing secret or key, and pasting those into a website is a bad idea. Verify signatures in your own code with a maintained library.

What do exp, iat and nbf mean?

exp is when the token expires, iat when it was issued and nbf the time before which it must not be accepted. All three are Unix timestamps in seconds.

Why does my token have five parts?

That is an encrypted token (JWE). Its header can be read, but the payload is encrypted and cannot be decoded without the key.