Free JWT Decoder
Something not working? Report a problem
About the JWT Decoder
Decode a JSON Web Token's header and payload with readable dates and an expiry check — entirely in your browser, so your token never leaves your device.
How to use the JWT Decoder
- 1Paste your JWT (the long eyJ… string) into the box.
- 2The decoded header and payload appear instantly, with timestamps turned into readable dates.
- 3Check the expiry badge to see whether the token is still valid.
Frequently asked questions
Is it safe to paste a real token here?
Yes — decoding happens entirely in your browser and the token is never sent anywhere. Still, treat live production tokens like passwords: decode them, don't share them.
What is a JWT?
A JSON Web Token — three Base64-encoded parts (header.payload.signature) that carry signed claims, most commonly "who is logged in" between your app and an API.
Does this verify the token's signature?
No — verification needs the secret or public key, and doing it in a browser tool would teach bad habits. This tool decodes and inspects; your server should always verify.
Why can everyone read my JWT's contents?
Because JWTs are encoded, not encrypted — the signature proves who issued the token, not that it's secret. That's why you should never put passwords or private data in a JWT payload.
What are iat, exp and nbf?
Standard timing claims, as Unix timestamps: iat is when the token was issued, exp when it expires, and nbf the time before which it must be rejected. This tool converts each into a readable date.