Decode a JSON Web Token to read its header, payload and expiry. Nothing is uploaded — decoding happens in your browser.
Decoding a JWT does not verify it. The signature is shown but not checked — anyone can read a token's contents, which is why you should never put secrets in one.
Processed on your device. This file is never uploaded.
1Paste your JWT into the box — it stays in your browser.
2Read the decoded header and payload below, formatted as JSON.
3Check the expiry and issued-at times, shown in your local time.
What a JWT actually is
A JSON Web Token is three base64url-encoded strings joined by dots: a header, a payload, and a signature. The header and payload are plain JSON that has been encoded, not encrypted — so decoding them back to readable JSON needs no key and no server. This tool does exactly that split-and-decode in your browser.
Decoding is not verifying
Reading a token and trusting a token are two different things. Anyone can decode the payload; only the party holding the signing key can confirm the signature is genuine. That check belongs on your backend, where the secret lives. Use this decoder to inspect and debug what a token carries — the claims, the algorithm, the expiry — not to authenticate it.