Generators
JWT Decoder
Decode a Token
Tool features
4 features
Instant Decoding
Decode JWT tokens instantly in your browser — no data sent to servers
Expiry Detection
Automatically detect token expiration and show time remaining
Claim Inspector
View all standard and custom claims with explanations
Structure View
Color-coded header, payload, and signature breakdown
What is a JWT & how it works
A JSON Web Token (JWT) is a compact token made of three Base64url parts separated by dots: a header naming the signing algorithm, a payload of claims such as the user ID and expiry, and a signature that proves the first two have not been altered.
The header and payload are only encoded, not encrypted, so anyone holding a token can read them. Decoding shows you exactly what a token claims and when it expires. It does not verify the signature: only the service holding the secret or public key can do that, so never trust a decoded token's claims on their own.
exp / nbf / iat
Expiry, not-before and issued-at times, in Unix seconds.
alg
The signing algorithm in the header, e.g. HS256 or RS256.
Signature
Checked by the server with its key; decoding alone does not validate it.
How to use this tool
1
Paste the token
Paste the full JWT, three dot-separated parts starting with eyJ.
2
Read the header
Check the algorithm and key ID the token claims to use.
3
Inspect the claims
Review the payload claims, with exp, nbf and iat shown as readable dates.
4
Check expiry
See whether the token is currently valid, expired or not yet active.
Related tools
3 tools
JWT Token Generator
Generate JSON Web Tokens (JWT) with customizable headers, payload, and signatures
Base64 Encoder Decoder
Encode and decode text or data to/from Base64 format with file support
URL Encoder / Decoder
Encode and decode URLs online — convert special characters to percent-encoding with batch mode and encodeURIComponent or encodeURI support
Frequently asked questions
5 Q&A
No. Decoding only reads the header and payload. Verification checks the signature with the issuer’s secret or public key, which your API must do on every request.
The payload is Base64url-encoded, not encrypted. Do not put secrets or sensitive personal data in a JWT. If the contents must be private, use an encrypted JWE instead.
The current time is past the
exp claim, so servers will reject it. The client should use its refresh token or sign in again.HS256 signs with a shared secret that both issuer and verifier hold. RS256 signs with a private key and verifies with a public key, so verifiers never need the signing secret.