JWT Decoder
Decode JSON Web Tokens, see every claim explained and whether the token has expired, verify the signature with a secret or public key, and create test tokens.
Runs in your browser. Nothing you add is uploaded.
What the JWT Decoder does
A JSON Web Token is three Base64URL-encoded segments separated by dots: a header describing the signing algorithm, a payload of claims, and a signature. The first two are readable by anyone — a JWT is signed, not encrypted. This tool decodes the header and payload, explains every claim in plain words, shows whether the token is valid, expired or not yet valid, and verifies the signature when you give it the secret or the issuer's public key (HS, RS, PS, ES and EdDSA algorithms, with PEM, JWK or JWKS keys). It can also create and sign test tokens. Everything happens in your browser with its built-in Web Crypto; tokens and keys are never sent anywhere.
How to decode and verify a JWT
- Paste the token. A “Bearer ” prefix, quotes or line breaks copied along with it are ignored.
- Check the status: whether it has expired or isn't valid yet, when it was issued and how long it lasts.
- Read the claims table — each value is explained, and times are shown as dates in your time zone.
- To confirm it's genuine, enter the secret (for HS256) or paste the issuer's public key or JWKS (for RS256, ES256 and others). A matching signature proves the token hasn't been changed.
- To make a test token instead, switch to Create a token, edit the claims and sign it with a secret or a generated test key.
The JWT Decoder runs entirely in your browser — nothing you enter is uploaded, stored, or logged.
When to use it
Diagnosing 401 responses
When an API rejects a token, decoding it usually explains why immediately: the 'exp' claim is in the past, or the 'aud' does not match the service you are calling.
Verifying what an identity provider actually issues
OIDC providers vary in which claims they include. Decoding a real token is faster than reading the documentation to find out whether email or roles are present.
Checking token lifetime during development
Comparing 'iat' and 'exp' shows the configured lifetime, which is useful when a session expires sooner than expected.
Good to know
- 'exp' and 'iat' are seconds since the Unix epoch. Multiply by 1000 before passing them to JavaScript's Date constructor.
- An 'alg' value of 'none' is a red flag — it indicates an unsigned token, which no production verifier should accept.
- Decoding is not verification. A decoded token that looks correct may still have an invalid signature.
- Never paste a production token belonging to a real user into an online decoder that sends data to a server. This one does not.
Frequently asked questions
Is it safe to paste JWT tokens here?
Does decoding a JWT verify its signature?
Is it safe to paste a token here?
Why is my JWT payload readable by anyone?
What do the standard claim names mean?
Why does my token have only two segments?
Related tools
HTTP Header Analyzer
Paste HTTP headers to see what each means and what to fix.
Regex Builder
Build a regular expression from blocks, with live matches.
SQL Formatter
Format, beautify, and minify SQL queries for Postgres, MySQL, and SQLite.
JSON to YAML Converter
Convert bidirectional JSON to YAML and YAML to JSON with presets.