JWT Decoder
Decode the readable parts of a JSON Web Token and inspect common time claims without sending the token to a server.
Local processing. Your data stays in this browser.
Decoding does not verify the token signature. Never trust a JWT until your application verifies it.
How to use it
- Paste a JWT into the input.
- Review its decoded header and payload.
- Check exp and iat timestamps, then verify the signature in your application.
Example
Input
eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjM0IiwibmFtZSI6Ik5hbWluYyJ9.signatureOutput
Header and payload JSON, plus readable time claims when present.
Common questions
- Does decoding verify a JWT signature?
- No. Decoding only reads Base64URL data. Trust a token only after your server verifies its signature and claims.
- Is my token transmitted anywhere?
- No. The token is decoded inside your browser and is never stored by this site.