Decode and inspect JSON Web Token header and payload.
Updated
Decode a JSON Web Token to inspect its header and payload, with the iat, nbf, and exp timestamps converted to UTC dates. Decoding happens locally — your token is never sent anywhere.
Runs entirely in your browser — nothing is uploaded.
A JSON Web Token, or JWT, is a compact string used to pass identity and permission claims between systems, made of two or three parts separated by dots: a header describing the token type and signing algorithm, a payload carrying the claims, and usually a signature. The first two parts are just Base64url-encoded JSON, not encrypted, so anyone holding the token can read them. This decoder does exactly that, in your browser, as you type: it decodes the header and payload, pretty-prints each as JSON with its own copy button, and converts the iat, nbf, and exp claims from Unix seconds into UTC dates. It does not verify the signature, so it can tell you what a token claims but never whether the claim is genuine or the token has been tampered with; use it for debugging, not for trusting input. It also does not check whether exp has passed. Tokens are never sent anywhere.
No — verifying a signature requires the secret or key. This tool decodes and displays the token's contents only.
No. Decoding is done entirely in your browser, so it's safe for sensitive tokens.
No. It converts the exp claim into a UTC date so you can read it, but it does not compare that date with the current time or label the token valid or expired. Check the date yourself, and remember that an unexpired token can still be forged if the signature was never verified.