JWT Decoder
Decode JSON Web Tokens instantly: view header, payload and signature, turn exp/iat/nbf into dates and spot expired tokens. Runs entirely in your browser.
Paste an access token from a login response, an Authorization header or a log line and see what is inside it in a second. The decoder is built for the everyday debugging loop of API authentication: checking which user and scopes a token carries, why a request is rejected as expired, and which signing algorithm your identity provider actually used.
// JWT Decoder: Features
What a JWT is
A JSON Web Token (JWT, defined in RFC 7519) is a compact, URL-safe string made of three parts separated by dots: a header, a payload and a signature. The header and payload are JSON objects encoded with Base64URL, and the signature is computed over the first two parts with a secret or private key. JWTs are the standard token format in OAuth 2.0 and OpenID Connect, so you meet them as access tokens, ID tokens and session tokens issued by Auth0, AWS Cognito, Azure AD, Keycloak, Firebase and most home-grown APIs.
Header, payload and signature at a glance
As soon as you paste a token, the tool splits it into its three segments and colors them so you can see where the header ends and the payload begins. Both JSON parts are decoded and pretty-printed with two-space indentation. The header typically shows the algorithm (alg) and type (typ), sometimes a key ID (kid). The payload holds the claims: subject (sub), issuer (iss), audience (aud), scopes or roles and the time-based claims. The raw signature segment is shown separately so you can compare it against another token or log entry.
Time claims converted to human dates
The exp (expiration), iat (issued at) and nbf (not before) claims are Unix timestamps in seconds, which are hard to read by eye. The decoder lists each one as a readable date and time in your browser's local time zone, including the zone abbreviation. If the current time is already past exp, a clear warning marks the token as expired, which is the single most common reason an API answers 401. When your team is spread across regions, the Time Zone Converter helps translate an expiry time into everyone's local clock.
Decoding is not verification
This tool decodes tokens; it does not verify signatures. Verification needs the shared secret (HS256) or the issuer's public key (RS256, ES256), and handling those keys inside a browser page would be both impractical and unsafe. Always verify signatures on the server with a maintained library such as jose, jsonwebtoken, PyJWT or the JWT support in your framework, and reject tokens whose header says alg: none. Treat the decoded payload as untrusted data until the signature has been checked.
Is it safe to paste a production token?
All decoding happens in JavaScript on your machine. The token you paste is never sent to a server, stored or logged, which makes it safe to inspect production access tokens, internal service tokens and tokens that contain user identifiers. The tool also keeps no history, so closing the tab is enough to discard what you pasted.
// JWT Decoder: FAQ
How do I decode a JWT with this tool?
- Paste the full token, the string that looks like xxxxx.yyyyy.zzzzz, into the input box. The header and payload are decoded and displayed immediately as formatted JSON, the signature segment is shown as-is, and any exp, iat or nbf claims are listed as readable dates. Use the copy button next to each section to grab the JSON for a bug report or a test fixture.
Can I paste the whole Authorization header, including "Bearer"?
- No. Paste only the token itself. The decoder splits the input on dots and Base64URL-decodes each part, so a leading "Bearer " prefix ends up inside the first segment and the token is reported as invalid. Copy just the part after the space. If you are working from a curl command, the cURL Converter shows the header values clearly so you can pick the token out.
Does the tool verify the signature?
- No. It only decodes the header and payload. Verifying a signature requires the HMAC secret for HS256 or the public key for RS256 and ES256, and a browser page is not the right place to handle those. Verify on the server, or with the official SDK of your identity provider, typically by fetching the keys from the JWKS endpoint at /.well-known/jwks.json and letting the library check the alg, kid, issuer and audience.
Why does it say my token is expired?
- The tool compares the exp claim, a Unix timestamp in seconds, with your computer's current time. If exp is in the past, the token is expired and most APIs will reject it with 401 Unauthorized. If you believe the token should still be valid, check that your system clock is correct and that the issuer's clock skew allowance covers the difference. Access tokens commonly live 5 to 60 minutes, so an expired result is normal for a token copied from an old log.
Are exp and iat in seconds or milliseconds?
- The JWT specification defines exp, iat and nbf as NumericDate values, which are seconds since the Unix epoch in UTC. JavaScript's Date.now() returns milliseconds, and mixing the two is a classic bug. This decoder treats the values as seconds. If the displayed date is thousands of years in the future, the token was almost certainly issued with a millisecond value by mistake.
Is it safe to put sensitive data in a JWT payload?
- No. The payload is only Base64URL-encoded, not encrypted, so anyone who holds the token can read it with a tool like this one. Never put passwords, card numbers, API secrets or private personal data in the claims. If confidentiality is required, use an encrypted JWE token or keep the data server-side and issue an opaque reference token instead.
What does alg: none in the header mean?
- It declares that the token carries no signature. This was exploited in the past when servers accepted such tokens without checking, letting an attacker forge any claims they liked. Modern libraries reject alg: none by default, and you should configure your verifier with an explicit allowlist of algorithms. If you see alg: none on a token your system accepted, treat it as a security incident.
HS256, RS256 or ES256: which should I use?
- HS256 uses a single shared secret, which is simple when the same service both issues and verifies tokens but becomes risky once several services need the secret. RS256 signs with a private key and verifies with a public key, so resource servers can validate tokens without being able to mint them; this is the usual choice for OAuth providers and microservices. ES256 offers the same asymmetric model with smaller keys and signatures and is increasingly the default in OpenID Connect deployments.
Why is my token reported as invalid?
- A token is rejected when it does not have exactly three dot-separated parts, when a part is not valid Base64URL, or when the decoded header or payload is not valid JSON. Common causes are a truncated copy, a trailing quote or comma from a JSON body, line breaks inserted by an email client, or a token that is actually an opaque string rather than a JWT. Copy the token again directly from the response or header.
Is the token sent to a server?
- No. Decoding runs entirely in your browser. The token is never sent over the network, never stored, and never included in analytics. Production tokens, tokens containing user IDs and internal service credentials can be inspected safely. Close the tab and the pasted value is gone.
// How to Use JWT Decoder
-
Paste the token
Copy the raw JWT, the three dot-separated Base64URL segments, from your API response, browser storage or Authorization header, and paste it into the input box. Leave out the "Bearer " prefix.
-
Read the decoded result
The header and payload appear as formatted JSON, and the signature segment is listed below them. Any exp, iat and nbf claims are shown as local dates, and an expired token is flagged with a warning so you know immediately whether a 401 is caused by expiry.
-
Copy the header or payload
Use the copy button on the header, payload or signature to place that section on your clipboard for a ticket, a test fixture or a message to a teammate. Press CLEAR to reset the tool before pasting the next token.
Category Security