1. Home
  2. Developer
  3. JWT Decoder

JWT Decoder

Read a JWT and check when it expires — the token is never sent anywhere.

Runs in your browser · No upload Works offline
The signature is NOT verified. Anyone can decode a JWT — to trust its contents, verify the signature with the key on your server. The token never leaves this browser.
Algorithm
HS256 · HMAC — one shared secret signs and verifies
Type (typ)
JWT
Subject (sub)
user_8f3a2c
Header
{ "alg": "HS256", "typ": "JWT" }
Payload
{ "sub": "user_8f3a2c", "name": "Jane Doe", "email": "jane@example.com", "role": "admin", "iat": 1767225600, "nbf": 1767225600, "exp": 1798761600 }
Time claims
ClaimMeaningUnix (s)UTC (ISO 8601)Local timeRelative
iatIssued at17672256002026-01-01T00:00:00.000Z——
nbfNot before17672256002026-01-01T00:00:00.000Z——
expExpires17987616002027-01-01T00:00:00.000Z——
Signature — not verified
c-HFJMTGsjmWupVIKK8hYIKX3VPa1eI_xcd_qm5ELiI

How to use

  1. Paste a JWT into the box. If you copied it from an Authorization: Bearer eyJ... header, the Bearer prefix is fine.
  2. The header and payload appear as formatted JSON, with key values — algorithm (alg), type (typ), issuer (iss), subject (sub) — summarized above them.
  3. iat (issued at), nbf (not before) and exp (expires) are converted to UTC, your local time and relative time such as “in 3 hours”. An expired token gets a red warning.

What’s inside a JWT

A JWT (JSON Web Token, RFC 7519) has three dot-separated parts. The first two are just base64url-encoded JSON — they are not encrypted.

Part Contains Example
Header Signing algorithm and token type {"alg":"HS256","typ":"JWT"}
Payload Claims: user ID, roles, expiry and so on {"sub":"user_8f3a2c","exp":1798761600}
Signature Header + payload signed with a key c-HFJMTG...

Time claims are seconds since 1970-01-01 00:00:00 UTC (NumericDate). exp: 1798761600 is 2027-01-01 00:00:00 UTC, or 2026-12-31 7:00 PM in New York. A common bug is putting milliseconds there, which pushes the expiry tens of thousands of years into the future. To convert a single number, use the Unix Timestamp Converter.

Things to know

  • This tool does not verify the signature. Anyone can edit a payload and re-encode it, so never make authorization decisions based on what you see here. Verification belongs on your server, with the shared secret (HS256) or the public key (RS256, ES256).
  • Don’t put secrets in the payload. Anyone who holds the token can decode and read it.
  • alg: none means the token is unsigned. If a server accepts it, tokens can be forged, so the tool flags it.
  • A token with five dot-separated parts is an encrypted JWE and can’t be read without the key.

FAQ

Is it safe to paste a production token?

Decoding happens in JavaScript inside your browser, and the token is never transmitted. Still, a live access token works like a password, so clear it when you’re screen-sharing or on a shared computer.

What time is the expiry checked against?

Your device’s clock. Following RFC 7519, a token is expired once the current time reaches exp, and not yet valid before nbf. If your clock and the server’s differ, results can be off by seconds or minutes.

Can I edit the payload?

You can re-encode edited JSON with the URL-safe option of the Base64 Encoder, but the signature will no longer match and the server will reject it. Test tokens should be issued with the server’s key.

Coming soon

Can't find the tool you need?

Tell us what you want to do. We build the most requested tools first.