Paste the token
From an Authorization header, a cookie, a log or a login response.
Paste a JWT and see its header and payload as readable JSON, with the dates explained and a warning if it has expired. Enter the secret to check an HS256 signature. All in your browser.
100% private — the token is decoded in your browser and never sent anywhere.
Keep going with your result in another tool. Nothing is uploaded.
From an Authorization header, a cookie, a log or a login response.
Header, payload and claims, with expiry and dates in your own language.
Enter the secret to verify HS256, HS384 or HS512.
A JSON Web Token, or JWT, is the compact string that many applications hand out after you log in and that you send back with each request, typically in an Authorization header. It looks like a long jumble of characters with two dots in it, but it is just three pieces of encoded data: a header that describes the token, a payload that carries information, and a signature. When something goes wrong with authentication, looking inside the token is the fastest way to see whether it has expired, who it was issued to and what it claims.
The expiry (exp), not-before (nbf) and issued-at (iat) claims are stored as numbers of seconds since 1970, which nobody can read. This tool converts them to a full date and time, says how long ago or how far in the future that is, and shows a banner when the token has expired or is not yet valid, the most common causes of a mysterious 401 error.
Decoding does not need any key, because the header and payload are only encoded, not encrypted. To check that the token is genuine you need the key. If the token uses a shared secret (HS256, HS384 or HS512), type the secret and the tool tells you whether the signature is valid. Tokens signed with a private key, such as RS256 or ES256, need the public key and cannot be verified here.
A common misunderstanding is that a JWT is secret. It is not: anyone who holds the token can read its payload, as this tool shows. Do not put passwords or sensitive data in a JWT unless it is also encrypted. Treat a live token like a password too: do not paste it into tools that send it to a server. This one works entirely in your browser.
The tool does not verify public-key signatures, check the audience or issuer against your expectations or make any request to an identity provider. Successful decoding is not proof of validity. To format the JSON further, use the JSON formatter.
More utilities that also run without leaving your browser.