JWT decoder

Paste a JSON Web Token to read its header and payload, see when it was issued and when it expires, and check an HS256 signature. Everything happens in your browser.

  • 100% free
  • Runs in your browser
  • No uploads
Decoded on this device. Nothing is sent.

Decoded token

The header, payload and the issued, not-before and expiry times appear here. Decoding doesn't check the signature; add the secret on the left to do that for HS256 tokens.

How to decode a JWT

  1. Paste the token. It starts with eyJ. A full Authorization header value with Bearer in front works too.
  2. Read the result. The header and payload are shown as formatted JSON, with exp, iat and nbf turned into dates in your time zone and UTC.
  3. Check the expiry. The status line says whether the token has expired or isn't valid yet, and by how long.
  4. Verify, if you have the secret. For HS256, HS384 or HS512 tokens, type the secret to see whether the signature matches.

What's inside a JWT

A signed JWT has three parts separated by dots: header.payload.signature. The header and payload are JSON, each encoded with Base64url (the URL-safe Base64 alphabet without padding). The signature is computed over the exact text header.payload, so changing a single character of either part makes it fail.

For HS256 the signature is HMAC-SHA256(secret, header + "." + payload), Base64url-encoded. A token with five parts is an encrypted JWE instead: its payload can't be read without the decryption key.

Registered claims

ClaimMeaningExample
issIssuer: who created the tokenhttps://auth.example.com
subSubject: usually the user iduser_123
audAudience: the API the token is forapi.example.com
expExpiry time, seconds since 19701700003600 (14 Nov 2023, 23:13:20 UTC)
nbfNot valid before this time1700000000
iatIssued at1700000000 (14 Nov 2023, 22:13:20 UTC)
jtiUnique token id, used to block reuse9f1c…

Common JWT mistakes

  • Putting secrets in the payload. Anyone holding the token can read it. Keep only ids and permissions there.
  • Accepting alg "none". An unsigned token can be forged by anyone. Servers should accept only the algorithm they expect.
  • Weak HS256 secrets. A short or dictionary secret can be guessed offline from one token. Use at least 32 random bytes.
  • Clock skew. Servers whose clocks differ by a minute can reject fresh tokens; most libraries allow a small leeway. Convert any time with the Unix timestamp converter.

Frequently asked questions

Is it safe to paste a real token here?

The token is decoded by JavaScript on this page and is never sent anywhere, so it doesn't leave your device. Even so, a live token is a password for as long as it's valid: avoid pasting production tokens into any website you don't control, and prefer expired or test tokens when you only need to read the claims.

Does decoding a JWT verify it?

No. The header and payload are only Base64url-encoded, so anyone can read them without a key. Whether the token is genuine depends on the signature. Decoding shows what the token claims; only checking the signature with the right key shows the claims weren't changed.

How do I verify an HS256 signature?

Paste the token, then type the shared secret in the box. The tool recomputes the HMAC-SHA256 of the header and payload with your browser's Web Crypto and compares it with the signature. HS384 and HS512 work the same way. Tick the Base64 box if your secret is stored Base64-encoded.

Can it verify RS256 or ES256 tokens?

Not yet. Those are signed with a private key and checked with a public key (often published at a JWKS URL). This tool decodes them fully but only checks HMAC signatures, so it never needs to fetch anything.

Why does my token say it expired in 1970 or in the far future?

JWT times (exp, iat, nbf) are seconds since 1 January 1970 UTC. A value in milliseconds is 1,000 times too big and lands tens of thousands of years ahead; the tool warns when it sees one. A very small number usually means the time was set in minutes or left as 0.

Learn more