Skip to content
ToolboxHere home

JWT decoder

Paste a JSON Web Token to decode it: a viewer for the header, every claim with its meaning, and whether the token is still valid, expired or not yet valid. The signature can be checked with a shared secret or a public key, on your device only.

  • Nothing you type leaves your device
  • 100% free
  • No sign-up
  • Instant results
JWT DecoderRead a JWT's header and claims, see when it expires, and check the signature with a secret or public key on your device.Starting… the tool runs entirely in your browser and needs JavaScript.

How to use JWT Decoder

  1. Paste the token, with or without the word Bearer. The three parts are coloured: header, payload, signature.
  2. Read the answer first: "Expires in 2 hours" or "Expired 3 days ago", with the exp, iat and nbf times in your zone and UTC.
  3. Read the claims in the table: sub, iss, aud, scope and the rest, each explained. Copy the payload as JSON if you need it.
  4. To check the signature, paste the shared secret (HS256, HS384, HS512) or the public key as PEM (RS, PS, ES) and tap Check.

Why use JWT Decoder

Expiry answered first

The one thing most people came to learn, in plain words, with the exact times underneath.

Claims explained

Standard claims (iss, sub, aud, exp, nbf, iat, jti) and common ones (scope, roles, email, kid) each carry a one-line meaning.

Signature check on the device

HMAC with a secret or RSA, RSA-PSS and ECDSA with a public key, using the browser's Web Crypto; the key is never stored or sent.

Plain errors

Two parts, five parts (an encrypted JWE), or a part that is not Base64: the page says so instead of failing silently.

About this tool

A JSON Web Token is three Base64 parts joined by dots: a header naming the algorithm, a payload of claims about the user and the session, and a signature the server made with its key. The first two parts are readable by anyone, which is why a token must never carry a password or card number, and why reading one needs no key. The signature is what a server checks before trusting the claims.

This decoder shows the header and payload, turns exp, iat and nbf into dates and a verdict, and explains each claim. If you have the secret or the public key it can also verify the signature, on your device, with the browser's Web Crypto: the popular big-brand debugger works the same way, but here the page makes no requests at all while you work, so pasting a production token is safe.

Frequently asked questions

Is it safe to paste a real token here?

The page makes no network requests while you work: the token, the secret and the key stay in your browser. Even so, treat any token you paste as sensitive and revoke it if it was shared.

Why can it read the token without the secret?

The header and payload are only Base64-encoded, not encrypted. The secret is needed only to make or check the signature.

How do I check the signature?

For HS256, HS384 and HS512 paste the shared secret. For RS256, PS256, ES256 and their 384/512 forms paste the public key in PEM (-----BEGIN PUBLIC KEY-----). The page says whether the signature matches.

What does "not valid yet" mean?

The nbf (not before) claim is in the future, often because the issuing server's clock is ahead of yours.

Can it read an encrypted token (JWE)?

No. A JWE has five parts and needs the decryption key; this page reads signed tokens (JWS), which are the common kind.

Is it safe to decode a JWT online here?

Yes. The token is decoded in your browser and never sent anywhere, so it is safer than pasting it into a site that sends it to a server.

Related tools