Skip to content
🔐

JWT Decoder

Decode the header and payload of a JSON Web Token and see the claims with dates.

This only decodes a token, it does not verify the signature. Anything here can be edited by whoever made the token, so never trust a decoded value for authentication. Use a server side library to verify.

Algorithm

-

Type

-

Expires

-

Status

-

Standard claims

Nothing decoded yet.

A token is three parts separated by dots: a base64url header, a base64url payload, and a signature. Only the first two are readable without the signing key. The alg: none case is a well known attack, so treat any token you receive as untrusted input until it is verified properly.

What Is JWT Decoder?

The JWT Decoder decodes the header and payload of a JSON Web Token and shows the standard claims such as issuer, subject, and expiry, with the timestamps converted into readable dates and an expired or valid marker.

Who Uses the JWT Decoder?

Developers use it to see what a token actually contains when debugging an authentication problem, and to check whether an expiry claim has already passed.

How to Use the JWT Decoder

  1. Paste the token.
  2. Read the decoded header and payload.
  3. Check the standard claims and whether the token has expired.

Why Choose Our JWT Decoder?

  • Standard claims with their meanings
  • Expiry and issue times as readable dates
  • Works entirely offline, nothing is sent anywhere

Try the JWT Decoder above — it is free, fast, and works on any device. Bookmark this page to return whenever you need it.