JWT Decoder Online
Paste a JSON Web Token to read what it actually contains — header and payload as formatted JSON, with expiry and not-before translated into plain language.
Token
Decoded
About this tool
A JWT is three Base64url segments joined by dots: header, payload and signature. The first two are just encoded JSON, so any token can be read without a key — which is the point of this page, and also the reason a token must never carry a secret. The signature is shown but not checked: verifying it requires the key, and a key does not belong in a browser tab. Time claims are the part people usually came for, so exp and nbf are compared against your clock and reported as 'expires in 3 days' rather than a raw epoch number.
How to use it
- 1Paste the token into the left panel — with or without a Bearer prefix, it is trimmed.
- 2Read the decoded header and payload on the right; the status bar carries the expiry.
- 3Switch to Tree if the payload is large and you want to fold parts of it away.
Frequently asked questions
›Does this verify the signature?
No, and no browser tool can. Verification needs the secret or the public key, and pasting a secret into a web page is exactly what you should not do. This decodes the token so you can read what it claims; verify it on the server that holds the key.
›Is a JWT encrypted?
No. The header and payload are Base64url — encoding, not encryption. Anyone holding the token can read every claim in it, which is why a JWT should never carry a password, a card number or anything else secret.
›What do iat, exp and nbf mean?
Issued-at, expiry and not-before, all in seconds since the Unix epoch. This page turns exp and nbf into plain language — "expires in 3 days", "expired 2 hours ago" — using your own clock.
›Why does my token fail to decode?
Usually a truncated copy: a JWT needs exactly three dot-separated parts. A "Bearer " prefix left on the front will also break it, as will a token that was URL-encoded somewhere along the way.
›Is my token sent anywhere?
No. Decoding happens entirely in your browser — nothing is uploaded, logged or stored. That matters more here than on most pages, since a live token is a credential.