Decoded locally. The signature is not verified.
Status
Paste a token to decode the header and payload.
Developer Tools
Decode a JWT header and payload in your browser and read expiry, issued-at, and claims. The signature is not verified. Free, fast, and built for a clean browser workflow.
Decoded locally. The signature is not verified.
Status
Paste a token to decode the header and payload.
Related tools
Format and minify JSON locally with indent controls, validation feedback, copy, and download.
Encode and decode Base64 with UTF-8 support and optional URL-safe alphabet—fully local.
Convert Unix timestamps and date-times locally with ISO, UTC, local, and millisecond views.
Validate JSON locally with clear errors, root-type summary, and copy or download actions.
A JSON Web Token has three segments: header, payload, and signature. This decoder Base64URL-decodes the first two so you can read the algorithm and claims.
Decoding does not prove the token is authentic. The signature is shown but not checked, because verification needs the issuer's secret or public key.
The token stays in your browser. Avoid pasting long-lived production tokens on a shared computer, and clear the page when you are done.
No. It only decodes the header and payload. Verification needs the signing key on your server.
No. Decoding uses the browser's Base64 and JSON parsers.
exp is a UTC Unix timestamp. The page formats it in your computer's time zone.
The page explains which segment failed to decode instead of showing partial garbage as valid JSON.
No. This page reads signed JWS tokens with a JSON header and payload, not encrypted JWE tokens.
Prefer short-lived dev tokens. The value stays local, but anyone who can see your screen can read the claims.