JWT Decoder
Paste a JSON Web Token to see its header, payload and claims, check if it has expired and verify the signature — without sending it anywhere.
Claims explained
| Claim | Value | Meaning |
|---|
Verify signature
Tokens and keys stay in your browser — decoding and signature checks run locally and nothing is sent to our server.
How to use the JWT Decoder
Paste a token
The three parts are color-coded.
Read the claims
Dates are converted and expiry is checked.
Verify (optional)
Enter the secret or public key to check the signature.
Why use our JWT Decoder?
Color-coded parts
Header, payload and signature at a glance.
Expiry check
exp, iat and nbf as dates with a live countdown.
Claim explanations
Standard claims like sub, aud and iss explained.
Signature verify
HS256/384/512, RS256/384/512 and ES256/384.
Security warnings
Flags alg “none” and tokens without expiry.
Never uploaded
Tokens are decoded and verified locally.
What is a JWT?
A JSON Web Token is a compact token with three Base64URL parts — header, payload and signature — used for login sessions and API authentication.
Is it safe to paste my token here?
Yes. Decoding and verification happen entirely in your browser; nothing is sent to our server. Still, treat production tokens like passwords.
Can anyone read a JWT?
Yes. The payload is only Base64URL-encoded, not encrypted. Never put passwords or secrets in a JWT payload.
How do I verify the signature?
For HS256 enter the shared secret; for RS256 or ES256 paste the public key in PEM format. The tool tells you if the signature is valid.
What do exp, iat and nbf mean?
exp is the expiry time, iat is when the token was issued, and nbf is the time before which it is not valid. All are Unix timestamps in seconds.
You may also like
Have a project in mind? Let’s build it together.
Get a free consultation and a fixed-price quote within 24 hours.