TanodTools

JWT decoder

Paste a JSON Web Token to read its header and payload, with expiry and issue times shown as real dates.

Runs entirely in your browser

Tokens up to 1 MB. Decoding only: the signature is shown but not checked.

How to decode a JWT

  1. Paste the token into the box. A leading Bearer and surrounding spaces or quotes are ignored.
  2. Read the header and payload below, and the expiry, not-before and issued-at times in your time zone and in UTC.
  3. Copy the decoded payload or header as formatted JSON if you need it elsewhere.

What is inside a JSON Web Token

A signed JWT is three pieces of Base64url text joined by dots: a header, a payload and a signature. The header and payload are just JSON written in Base64url, which is why anyone can read them. Base64url is an encoding, not encryption, so never put secrets in a JWT payload unless the token is encrypted.

The payload holds claims. Some names are registered: iss (who issued the token), sub (who it is about), aud (who it is meant for), exp (when it expires), nbf (not valid before), iat (when it was issued) and jti (a unique ID). Services add their own claims, such as roles, scopes or an email address.

The signature is what makes the claims trustworthy, and checking it needs the signing key, which only the issuer and the services that accept the token should hold. This decoder deliberately stops at reading: it shows what a token says and when it expires, which is usually what you need while debugging a login or an API call.

Tips

Questions

Does this check the signature?

No. This page only decodes the token. Anyone can create a token with any header and payload, so the contents shown here are claims, not proof. Only the service that holds the signing key (or the public key, for RS256 and ES256 tokens) can tell whether a token is genuine, and it must also check the expiry, audience and issuer.

Is it safe to paste a token here?

This page doesn't send the token anywhere: it is decoded by code running in your browser and is not stored. Even so, a live access token is a password for as long as it is valid. Avoid pasting production tokens into any website, and prefer expired or test tokens when you are debugging.

Why can't I read some tokens?

A token with five parts instead of three is an encrypted JWT (JWE). Its header is readable, but the payload is encrypted and can only be read with the recipient's key, so this tool shows the header and explains the parts. Other errors, such as a wrong number of parts or text that isn't valid Base64url or JSON, are reported with what went wrong.

How are the times worked out?

The exp, nbf and iat claims are NumericDates: seconds since 1 January 1970 UTC. They are shown in your device's time zone and in UTC, and compared with your device's clock to say whether the token has expired. If your clock is wrong, the relative times will be too. A value that looks like milliseconds is flagged, since that is a common bug.

What do alg, typ and kid mean?

alg is the signing algorithm, such as HS256 (a shared secret), RS256 or ES256 (a key pair). typ is usually JWT. kid is the key ID the issuer used, which tells a verifier which key to check the signature with. A token with alg set to none is unsigned and should never be accepted for anything that matters.