JWT Decoder
Paste a JSON Web Token to inspect its header and payload and see whether it is expired. Decoding happens locally in your browser - the token never leaves your device.
What is a JWT?
A JSON Web Token is a compact, URL-safe way to represent claims between two parties. It has three Base64URL-encoded parts separated by dots: a header (algorithm and type), a payload (the claims) and a signature.
Common claims
iss issuer, sub subject, aud audience, exp expiry time, nbf not-before time, iat issued-at time and jti token ID. Times are Unix timestamps in seconds.
Security note
A JWT payload is encoded, not encrypted - anyone holding the token can read it. Do not put secrets in it. This page decodes locally, but as a habit avoid pasting live production tokens into online tools.
Frequently asked questions
Does this JWT decoder verify the signature?
No. It decodes the header and payload only. Signature verification needs your secret or public key and should be done on your server.
Is it safe to paste my JWT here?
Decoding happens entirely in your browser and nothing is sent to a server. Still, treat live production tokens as sensitive and prefer expired or test tokens.
How do I know if a JWT has expired?
Check the exp claim, a Unix timestamp in seconds. If it is earlier than the current time, the token is expired. This tool shows the status automatically.
Need something custom built?Full-stack platforms, cloud infrastructure and AI agent automation — I'm available for freelance/consulting work.
Hire me →