Generators

JWT Decoder

Token Claims

Decode a Token

Paste your JWT token below. Decoding happens entirely in your browser — your token is never sent to our servers.

Tool features

Inspect JWT tokens with full transparency
4 features

Instant Decoding

Decode JWT tokens instantly in your browser — no data sent to servers

Expiry Detection

Automatically detect token expiration and show time remaining

Claim Inspector

View all standard and custom claims with explanations

Structure View

Color-coded header, payload, and signature breakdown

What is a JWT & how it works

The three parts of a JSON Web Token

A JSON Web Token (JWT) is a compact token made of three Base64url parts separated by dots: a header naming the signing algorithm, a payload of claims such as the user ID and expiry, and a signature that proves the first two have not been altered.

The header and payload are only encoded, not encrypted, so anyone holding a token can read them. Decoding shows you exactly what a token claims and when it expires. It does not verify the signature: only the service holding the secret or public key can do that, so never trust a decoded token's claims on their own.

exp / nbf / iat
Expiry, not-before and issued-at times, in Unix seconds.
alg
The signing algorithm in the header, e.g. HS256 or RS256.
Signature
Checked by the server with its key; decoding alone does not validate it.

How to use this tool

Decode and inspect a JWT in four steps
1
Paste the token
Paste the full JWT, three dot-separated parts starting with eyJ.
2
Read the header
Check the algorithm and key ID the token claims to use.
3
Inspect the claims
Review the payload claims, with exp, nbf and iat shown as readable dates.
4
Check expiry
See whether the token is currently valid, expired or not yet active.

Frequently asked questions

Common questions about JSON Web Tokens
5 Q&A

Decoding happens entirely in your browser and the token is never sent to ShowDNS. Still, a live token is a credential: prefer expired or test tokens, and never share one publicly.

No. Decoding only reads the header and payload. Verification checks the signature with the issuer’s secret or public key, which your API must do on every request.

The payload is Base64url-encoded, not encrypted. Do not put secrets or sensitive personal data in a JWT. If the contents must be private, use an encrypted JWE instead.

The current time is past the exp claim, so servers will reject it. The client should use its refresh token or sign in again.

HS256 signs with a shared secret that both issuer and verifier hold. RS256 signs with a private key and verifies with a public key, so verifiers never need the signing secret.