JWT Decoder
Decode JWT headers and payloads locally. Inspect exp, nbf and iat dates, copy readable JSON and troubleshoot token format errors without uploading your token.
Your result will appear here.
How to decode a JWT
- Paste the complete token with its three dot-separated parts, without the Bearer prefix.
- Inspect the JSON header and payload, then review any issuance, activation and expiry dates.
- Copy or download the decoded JSON. Verify signatures and access permissions in your application, not here.
Working with JWT Decoder
Decoding a JWT does not verify its signature. A readable token can still be forged, revoked or unacceptable to a service. Do not use decoded claims as proof of identity. Encrypted five-part JWE tokens require a different tool.
JWT example: read a payload without a signing key
- Input
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjMiLCJuYW1lIjoiSGVsbG8sIHdvcmxkISDwn5GLIiwiaWF0IjoxNzA0MDY3MjAwLCJleHAiOjE3MDQwNzA4MDB9.c2ln- Result
{ "header": { "alg": "HS256", "typ": "JWT" }, "payload": { "sub": "123", "name": "Hello, world! ๐", "iat": 1704067200, "exp": 1704070800 } }
Questions about JWT Decoder
Can I decode a JWT without the secret key?
Yes. A three-part JWT with a readable JSON payload uses Base64URL, not encryption. Reading it needs no key; verifying its signature does. This tool does not verify signatures.
What do exp, nbf and iat mean?
exp is the expiry time, nbf is the earliest activation time and iat is the issuance time. Their numeric values are Unix seconds, not milliseconds. When present, this tool displays them as UTC dates.
Why will my JWT not decode?
Paste the token alone, without Bearer, quotes or internal spaces. This tool expects three parts with JSON objects in the header and payload. Five-part encrypted JWE tokens and non-JWT access tokens are not supported.
Does a decoded JWT mean I can use it to sign in?
No. Readable claims and an expiry time in the future do not prove authenticity or access. The service must verify the signature and its own rules, including issuer, audience and revocation.
Are my files, tokens or text uploaded?
No. These tools process your input in your browser. The website serves the page and its code, but your input is not sent to a conversion server or saved in an account.
Related tools for your next step
- Base64URL Encoder & Decoder
Convert text to URL-safe Base64 with the - and _ alphabet. Encode or decode unpadded Base64URL strings.
- JSON Formatter, Minifier & Validator
Format, minify and validate JSON with exact large-number preservation, indentation options and recursive key sorting.
- Unix Timestamp Converter
Convert Unix seconds, milliseconds and ISO 8601 dates. View the same instant in UTC and any IANA time zone.
Common tasks and examples
- JSON Minifier
Compact JSON to one line while keeping string contents and exact numbers.
Explore all developer tools
Encoding & Files
Move between text, bytes, URLs and embedded images without changing your original data.
Base64 Encoder & Decoder
Encode UTF-8 text to Base64 or decode standard and URL-safe Base64. Control padding and line wrapping.
Base64URL Encoder & Decoder
Convert text to URL-safe Base64 with the - and _ alphabet. Encode or decode unpadded Base64URL strings.
Image to Base64
Convert PNG, JPEG, GIF, WebP, SVG and other recognised image files to Base64 Data URIs in your browser.
Base64 to Image
Decode a Base64 image or Data URI, preview supported image types and download the original image bytes.
File to Base64
Encode any file to a Base64 string, with optional Data URI prefix, padding and MIME line wrapping.
Base64 to File
Turn Base64 strings and Data URIs back into downloadable files without changing the decoded binary data.
URL Encoder & Decoder
Encode and decode URL components, complete URLs and form values. Handle percent escapes and spaces correctly.
HTML Entity Encoder & Decoder
Convert text and Unicode characters to HTML entities, or decode named and numeric HTML character references.
Unicode Inspector & Escape Converter
Inspect Unicode code points, UTF-8 bytes and UTF-16 units, or convert JavaScript Unicode escapes to readable text.
Data & Text Inspection
Read structured data, inspect tokens and understand exactly what changed.
JSON Formatter, Minifier & Validator
Format, minify and validate JSON with exact large-number preservation, indentation options and recursive key sorting.
Text Diff Checker
Compare two texts by line, word or character. Highlight additions and removals while retaining spaces and line breaks.
Regular Expression Tester
Test JavaScript regular expressions with flags, match positions, capture groups and named groups in your browser.
Hashes, IDs & Schedules
Check file integrity, generate identifiers and make sense of times and recurring schedules.
MD5 Hash & File Checksum
Calculate an MD5 hash for text or a local file, and compare it with an expected checksum.
SHA-1 Hash & File Checksum
Calculate SHA-1 hashes for UTF-8 text or files and compare the result with an expected checksum.
SHA-256 Hash & File Checksum
Generate SHA-256 hashes for text or files and check a downloaded file against its published checksum.
SHA-512 Hash & File Checksum
Calculate SHA-512 text and file hashes locally and compare full hexadecimal checksums.
CRC32 Checksum Calculator
Calculate standard CRC-32 checksums for text or files and compare eight-character hexadecimal results.
HMAC Generator
Generate HMAC-SHA-1, HMAC-SHA-256 and HMAC-SHA-512 with a UTF-8 or hexadecimal secret key.
UUID & GUID Generator
Generate random UUID v4 or time-ordered UUID v7 identifiers, individually or in batches.
Unix Timestamp Converter
Convert Unix seconds, milliseconds and ISO 8601 dates. View the same instant in UTC and any IANA time zone.
Cron Expression Parser
Validate five- or six-field Cron expressions and list upcoming runs in an IANA time zone, including daylight-saving changes.
Cron Expression Generator
Build a Cron expression from time fields or common presets, then preview its next scheduled times in your chosen zone.
Your input and files are processed on your device. Keep sensitive results out of shared clipboards and use a trusted device for private keys and tokens.