Home › Web & Security

JWT Decoder

Paste a JSON Web Token to decode its header and payload, with expiry and issued-at times rendered as readable timestamps and a clear note on what decoding does not prove.

0Segments
-Status
-Expires

Header

Payload

Decoding proves nothing about who signed this token - see the FAQ before you trust a value you read here.

Why the signature segment stays blank

A JWT is three base64url segments separated by dots: header, payload, signature. The first two are only encoded, never encrypted - anyone holding the token can read them, which is exactly what this page does. The third segment is a cryptographic signature over the first two, and checking it requires the server's secret or public key. This tool has neither, so it does not pretend to verify anything: it decodes, formats and displays, and tells you in the status field that the result is unverified.

That distinction matters when you debug an auth problem. A payload that decodes cleanly can still be expired, tampered with, or signed with the wrong key. What you can trust from this page is structural - the claim names, the types, the timestamp arithmetic - not authenticity.

Usage example

A request returns HTTP 401 and the error says the token expired, but the client code claims it refreshes every fifteen minutes. Paste the token here: the payload shows exp and iat converted to readable UTC, and the status field reads expired or valid based on your clock. If iat is hours old, the refresh never ran. If the claims look right and the token still fails on the server, the problem is the signing key or the audience claim - not the token body.

Claim names are worth a second look too: a token carrying role: "admin" in a payload the client never requested is a finding, not a formatting detail. Once you know what the token should contain, compare real tokens across environments with the text diff, and if you need a fresh test value, generate one with the UUID generator for the subject claim.

Frequently asked questions

Does this verify the token signature?

No, and it cannot. Verification needs the secret or public key that signed the token. This page decodes the encoded segments so you can inspect structure and timestamps; treat every value as unverified.

Is my token stored or logged?

No. Decoding happens in your browser with atob-style base64url decoding, and the page sends nothing anywhere. Session tokens are still credentials - avoid pasting a live production token into any online tool, this one included, if your policy forbids it.

Why does the payload show garbage instead of JSON?

A JWT uses base64url (- and _ instead of + and /) with no padding. The decoder handles that, so garbage output usually means the string you pasted is truncated, or it is not a JWT at all - count the dots: a token has exactly two.

Related tools

UUID Generator

Generate RFC 4122 UUIDs in v4 and v7 flavours, with bulk output and copy-to-clipboard.

SHA Hash Generator

Compute SHA-256, SHA-1 and MD5 digests of any text directly in the browser.

Base64 Encoder

Encode and decode Base64 for text and UTF-8 strings, with URL-safe output.