DEV

JWT Token Decoder

Paste a JSON Web Token to read its header and payload, with issued-at and expiry times converted to readable dates.

TOKEN
DECODED

          

How it works

A JWT is three Base64URL-encoded parts separated by dots: a header (the signing algorithm), a payload (the claims), and a signature. This tool decodes the first two and pretty-prints them as JSON. Standard time claims — iat (issued at), nbf (not before) and exp (expires) — are also shown as UTC dates.

Decoding is not verifying. Anyone can read a JWT's contents; only checking the signature against the right key proves a token is genuine and unmodified. This tool does not verify signatures, so never treat its output as proof of authenticity.

Frequently asked

Does this verify the token's signature?

No. It only decodes the header and payload. Verifying a signature requires the secret or public key and should be done on your server, not by pasting tokens into a web page.

Is it safe to paste a real token here?

Decoding happens entirely in your browser and nothing is sent anywhere. Even so, treat live tokens like passwords — prefer an expired or test token when you just need to check a token's structure.