PapaTools

Free JWT Decoder

Something not working? Report a problem

About the JWT Decoder

Decode a JSON Web Token's header and payload with readable dates and an expiry check — entirely in your browser, so your token never leaves your device.

How to use the JWT Decoder

  1. 1Paste your JWT (the long eyJ… string) into the box.
  2. 2The decoded header and payload appear instantly, with timestamps turned into readable dates.
  3. 3Check the expiry badge to see whether the token is still valid.

Frequently asked questions

Is it safe to paste a real token here?

Yes — decoding happens entirely in your browser and the token is never sent anywhere. Still, treat live production tokens like passwords: decode them, don't share them.

What is a JWT?

A JSON Web Token — three Base64-encoded parts (header.payload.signature) that carry signed claims, most commonly "who is logged in" between your app and an API.

Does this verify the token's signature?

No — verification needs the secret or public key, and doing it in a browser tool would teach bad habits. This tool decodes and inspects; your server should always verify.

Why can everyone read my JWT's contents?

Because JWTs are encoded, not encrypted — the signature proves who issued the token, not that it's secret. That's why you should never put passwords or private data in a JWT payload.

What are iat, exp and nbf?

Standard timing claims, as Unix timestamps: iat is when the token was issued, exp when it expires, and nbf the time before which it must be rejected. This tool converts each into a readable date.

More developer tools

View all