How to use JWT Decoder
- Paste the token, with or without the word Bearer. The three parts are coloured: header, payload, signature.
- Read the answer first: "Expires in 2 hours" or "Expired 3 days ago", with the exp, iat and nbf times in your zone and UTC.
- Read the claims in the table: sub, iss, aud, scope and the rest, each explained. Copy the payload as JSON if you need it.
- To check the signature, paste the shared secret (HS256, HS384, HS512) or the public key as PEM (RS, PS, ES) and tap Check.
Why use JWT Decoder
Expiry answered first
The one thing most people came to learn, in plain words, with the exact times underneath.
Claims explained
Standard claims (iss, sub, aud, exp, nbf, iat, jti) and common ones (scope, roles, email, kid) each carry a one-line meaning.
Signature check on the device
HMAC with a secret or RSA, RSA-PSS and ECDSA with a public key, using the browser's Web Crypto; the key is never stored or sent.
Plain errors
Two parts, five parts (an encrypted JWE), or a part that is not Base64: the page says so instead of failing silently.
About this tool
A JSON Web Token is three Base64 parts joined by dots: a header naming the algorithm, a payload of claims about the user and the session, and a signature the server made with its key. The first two parts are readable by anyone, which is why a token must never carry a password or card number, and why reading one needs no key. The signature is what a server checks before trusting the claims.
This decoder shows the header and payload, turns exp, iat and nbf into dates and a verdict, and explains each claim. If you have the secret or the public key it can also verify the signature, on your device, with the browser's Web Crypto: the popular big-brand debugger works the same way, but here the page makes no requests at all while you work, so pasting a production token is safe.
Frequently asked questions
Is it safe to paste a real token here?
The page makes no network requests while you work: the token, the secret and the key stay in your browser. Even so, treat any token you paste as sensitive and revoke it if it was shared.
Why can it read the token without the secret?
The header and payload are only Base64-encoded, not encrypted. The secret is needed only to make or check the signature.
How do I check the signature?
For HS256, HS384 and HS512 paste the shared secret. For RS256, PS256, ES256 and their 384/512 forms paste the public key in PEM (-----BEGIN PUBLIC KEY-----). The page says whether the signature matches.
What does "not valid yet" mean?
The nbf (not before) claim is in the future, often because the issuing server's clock is ahead of yours.
Can it read an encrypted token (JWE)?
No. A JWE has five parts and needs the decryption key; this page reads signed tokens (JWS), which are the common kind.
Is it safe to decode a JWT online here?
Yes. The token is decoded in your browser and never sent anywhere, so it is safer than pasting it into a site that sends it to a server.