JWT decoder
Paste a JSON Web Token to read its header and payload, with expiry and issue times shown as real dates.
Runs entirely in your browser
Signature not verified. This page decodes the token; it does not check that it is genuine. Anyone can create a token with any contents.
- Algorithm
- -
- Type
- -
- Key ID
- -
- Parts
- -
Times
| Claim | Your time zone, then UTC | Relative |
|---|
Claims
| Claim | Meaning | Value |
|---|
Tokens up to 1 MB. Decoding only: the signature is shown but not checked.
How to decode a JWT
- Paste the token into the box. A leading
Bearerand surrounding spaces or quotes are ignored. - Read the header and payload below, and the expiry, not-before and issued-at times in your time zone and in UTC.
- Copy the decoded payload or header as formatted JSON if you need it elsewhere.
What is inside a JSON Web Token
A signed JWT is three pieces of Base64url text joined by dots: a header, a payload and a signature. The header and payload are just JSON written in Base64url, which is why anyone can read them. Base64url is an encoding, not encryption, so never put secrets in a JWT payload unless the token is encrypted.
The payload holds claims. Some names are registered: iss (who issued the token), sub (who it is about), aud (who it is meant for), exp (when it expires), nbf (not valid before), iat (when it was issued) and jti (a unique ID). Services add their own claims, such as roles, scopes or an email address.
The signature is what makes the claims trustworthy, and checking it needs the signing key, which only the issuer and the services that accept the token should hold. This decoder deliberately stops at reading: it shows what a token says and when it expires, which is usually what you need while debugging a login or an API call.
Tips
- Convert any other Unix time to a date with the Unix timestamp converter.
- Format or check a large payload with the JSON formatter.
- Decode a single Base64url piece by hand with Base64 encode and decode.
Questions
Does this check the signature?
No. This page only decodes the token. Anyone can create a token with any header and payload, so the contents shown here are claims, not proof. Only the service that holds the signing key (or the public key, for RS256 and ES256 tokens) can tell whether a token is genuine, and it must also check the expiry, audience and issuer.
Is it safe to paste a token here?
This page doesn't send the token anywhere: it is decoded by code running in your browser and is not stored. Even so, a live access token is a password for as long as it is valid. Avoid pasting production tokens into any website, and prefer expired or test tokens when you are debugging.
Why can't I read some tokens?
A token with five parts instead of three is an encrypted JWT (JWE). Its header is readable, but the payload is encrypted and can only be read with the recipient's key, so this tool shows the header and explains the parts. Other errors, such as a wrong number of parts or text that isn't valid Base64url or JSON, are reported with what went wrong.
How are the times worked out?
The exp, nbf and iat claims are NumericDates: seconds since 1 January 1970 UTC. They are shown in your device's time zone and in UTC, and compared with your device's clock to say whether the token has expired. If your clock is wrong, the relative times will be too. A value that looks like milliseconds is flagged, since that is a common bug.
What do alg, typ and kid mean?
alg is the signing algorithm, such as HS256 (a shared secret), RS256 or ES256 (a key pair). typ is usually JWT. kid is the key ID the issuer used, which tells a verifier which key to check the signature with. A token with alg set to none is unsigned and should never be accepted for anything that matters.