Security

JWT Decoder

Decode the readable parts of a JSON Web Token and inspect common time claims without sending the token to a server.

Local processing. Your data stays in this browser.

Decoding does not verify the token signature. Never trust a JWT until your application verifies it.

How to use it

  • Paste a JWT into the input.
  • Review its decoded header and payload.
  • Check exp and iat timestamps, then verify the signature in your application.

Example

Input
eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjM0IiwibmFtZSI6Ik5hbWluYyJ9.signature
Output
Header and payload JSON, plus readable time claims when present.

Common questions

Does decoding verify a JWT signature?
No. Decoding only reads Base64URL data. Trust a token only after your server verifies its signature and claims.
Is my token transmitted anywhere?
No. The token is decoded inside your browser and is never stored by this site.