JWT decoder

Paste a JWT and see its header and payload as readable JSON, with the dates explained and a warning if it has expired. Enter the secret to check an HS256 signature. All in your browser.

  • Free
  • No sign-up
  • Runs in your browser
jwt-decoder

100% private — the token is decoded in your browser and never sent anywhere.

How it works

Paste the token

From an Authorization header, a cookie, a log or a login response.

Read it

Header, payload and claims, with expiry and dates in your own language.

Check the signature if you have the key

Enter the secret to verify HS256, HS384 or HS512.

What is inside this token?

A JSON Web Token, or JWT, is the compact string that many applications hand out after you log in and that you send back with each request, typically in an Authorization header. It looks like a long jumble of characters with two dots in it, but it is just three pieces of encoded data: a header that describes the token, a payload that carries information, and a signature. When something goes wrong with authentication, looking inside the token is the fastest way to see whether it has expired, who it was issued to and what it claims.

The three parts

  • Header: the algorithm used to sign the token, for example HS256 or RS256, and the token type.
  • Payload: the claims, such as the subject, the issuer, the audience and the times. It can also hold custom data such as a user id or roles.
  • Signature: proof that the header and payload have not been altered, made with a secret or a private key.

The dates, in plain language

The expiry (exp), not-before (nbf) and issued-at (iat) claims are stored as numbers of seconds since 1970, which nobody can read. This tool converts them to a full date and time, says how long ago or how far in the future that is, and shows a banner when the token has expired or is not yet valid, the most common causes of a mysterious 401 error.

Checking the signature

Decoding does not need any key, because the header and payload are only encoded, not encrypted. To check that the token is genuine you need the key. If the token uses a shared secret (HS256, HS384 or HS512), type the secret and the tool tells you whether the signature is valid. Tokens signed with a private key, such as RS256 or ES256, need the public key and cannot be verified here.

Anyone can read a JWT

A common misunderstanding is that a JWT is secret. It is not: anyone who holds the token can read its payload, as this tool shows. Do not put passwords or sensitive data in a JWT unless it is also encrypted. Treat a live token like a password too: do not paste it into tools that send it to a server. This one works entirely in your browser.

What it does not do

The tool does not verify public-key signatures, check the audience or issuer against your expectations or make any request to an identity provider. Successful decoding is not proof of validity. To format the JSON further, use the JSON formatter.

Frequently asked questions

How do I decode a JWT?
Paste the token. The header and payload appear as readable JSON, with the dates explained.
Can I tell if a JWT has expired?
Yes. If it has an exp claim, the tool shows the expiry date and a banner saying whether the token has expired.
Is it safe to paste my token here?
The token is decoded in your browser and not sent anywhere. Still, treat live tokens as secrets and use expired or test tokens when possible.
Can it verify the signature?
For HS256, HS384 and HS512, yes, if you enter the secret. Tokens signed with public keys cannot be verified here.
Is the payload of a JWT encrypted?
No, only encoded. Anyone with the token can read it, so never put secrets in it.
Is my token uploaded anywhere?
No. Everything happens in your browser.