How to use
- Paste a JWT into the box. If you copied it from an
Authorization: Bearer eyJ...header, theBearerprefix is fine. - The header and payload appear as formatted JSON, with key values — algorithm (alg), type (typ), issuer (iss), subject (sub) — summarized above them.
iat(issued at),nbf(not before) andexp(expires) are converted to UTC, your local time and relative time such as “in 3 hours”. An expired token gets a red warning.
What’s inside a JWT
A JWT (JSON Web Token, RFC 7519) has three dot-separated parts. The first two are just base64url-encoded JSON — they are not encrypted.
| Part | Contains | Example |
|---|---|---|
| Header | Signing algorithm and token type | {"alg":"HS256","typ":"JWT"} |
| Payload | Claims: user ID, roles, expiry and so on | {"sub":"user_8f3a2c","exp":1798761600} |
| Signature | Header + payload signed with a key | c-HFJMTG... |
Time claims are seconds since 1970-01-01 00:00:00 UTC (NumericDate). exp: 1798761600 is 2027-01-01 00:00:00 UTC, or 2026-12-31 7:00 PM in New York. A common bug is putting milliseconds there, which pushes the expiry tens of thousands of years into the future. To convert a single number, use the Unix Timestamp Converter.
Things to know
- This tool does not verify the signature. Anyone can edit a payload and re-encode it, so never make authorization decisions based on what you see here. Verification belongs on your server, with the shared secret (HS256) or the public key (RS256, ES256).
- Don’t put secrets in the payload. Anyone who holds the token can decode and read it.
alg: nonemeans the token is unsigned. If a server accepts it, tokens can be forged, so the tool flags it.- A token with five dot-separated parts is an encrypted JWE and can’t be read without the key.
FAQ
Is it safe to paste a production token?
Decoding happens in JavaScript inside your browser, and the token is never transmitted. Still, a live access token works like a password, so clear it when you’re screen-sharing or on a shared computer.
What time is the expiry checked against?
Your device’s clock. Following RFC 7519, a token is expired once the current time reaches exp, and not yet valid before nbf. If your clock and the server’s differ, results can be off by seconds or minutes.
Can I edit the payload?
You can re-encode edited JSON with the URL-safe option of the Base64 Encoder, but the signature will no longer match and the server will reject it. Test tokens should be issued with the server’s key.