JWT Decoder

Decode JWT headers and payloads locally. Inspect exp, nbf and iat dates, copy readable JSON and troubleshoot token format errors without uploading your token.

Inspect
0 characters
Result

Your result will appear here.

How to decode a JWT

  1. Paste the complete token with its three dot-separated parts, without the Bearer prefix.
  2. Inspect the JSON header and payload, then review any issuance, activation and expiry dates.
  3. Copy or download the decoded JSON. Verify signatures and access permissions in your application, not here.

Working with JWT Decoder

Decoding a JWT does not verify its signature. A readable token can still be forged, revoked or unacceptable to a service. Do not use decoded claims as proof of identity. Encrypted five-part JWE tokens require a different tool.

JWT example: read a payload without a signing key

Input
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjMiLCJuYW1lIjoiSGVsbG8sIHdvcmxkISDwn5GLIiwiaWF0IjoxNzA0MDY3MjAwLCJleHAiOjE3MDQwNzA4MDB9.c2ln
Result
{ "header": { "alg": "HS256", "typ": "JWT" }, "payload": { "sub": "123", "name": "Hello, world! ๐Ÿ‘‹", "iat": 1704067200, "exp": 1704070800 } }

Questions about JWT Decoder

Can I decode a JWT without the secret key?

Yes. A three-part JWT with a readable JSON payload uses Base64URL, not encryption. Reading it needs no key; verifying its signature does. This tool does not verify signatures.

What do exp, nbf and iat mean?

exp is the expiry time, nbf is the earliest activation time and iat is the issuance time. Their numeric values are Unix seconds, not milliseconds. When present, this tool displays them as UTC dates.

Why will my JWT not decode?

Paste the token alone, without Bearer, quotes or internal spaces. This tool expects three parts with JSON objects in the header and payload. Five-part encrypted JWE tokens and non-JWT access tokens are not supported.

Does a decoded JWT mean I can use it to sign in?

No. Readable claims and an expiry time in the future do not prove authenticity or access. The service must verify the signature and its own rules, including issuer, audience and revocation.

Are my files, tokens or text uploaded?

No. These tools process your input in your browser. The website serves the page and its code, but your input is not sent to a conversion server or saved in an account.

Common tasks and examples

  • JSON Minifier

    Compact JSON to one line while keeping string contents and exact numbers.

Explore all developer tools

Encoding & Files

Move between text, bytes, URLs and embedded images without changing your original data.

Data & Text Inspection

Read structured data, inspect tokens and understand exactly what changed.

Hashes, IDs & Schedules

Check file integrity, generate identifiers and make sense of times and recurring schedules.

Your input and files are processed on your device. Keep sensitive results out of shared clipboards and use a trusted device for private keys and tokens.