JWT decoder

Paste a JWT (JSON Web Token) and see what it contains: the header with the algorithm and the payload with the claims, formatted as JSON. Times such as exp and iat are shown as normal dates, and you see whether the token has expired. A leading Bearer is fine.

Show
Indent

How it works

  1. Paste your code

    Paste the code in the left box or open a file. No code to hand? Click Example.

  2. Instant result

    The result appears as you type. If there is an error, you see the line and character.

  3. Copy or download

    Copy the result with one click or save it as a file for your editor or project.

How is a JWT built?

A JWT has three parts with a dot between them: header.payload.signature. The first two are JSON encoded as base64url. Anyone can read them; they are not encrypted. So never put passwords or other secrets in a JWT. The signature only proves the content hasn't been changed.

Common claims

  • sub: who the token is about (the user).
  • iat: when the token was issued.
  • exp: until when it is valid.
  • nbf: from when it is valid.
  • iss and aud: who issued it and who it is meant for.

The times are Unix timestamps, seconds since 1 January 1970. You can convert them yourself with the Unix timestamp converter.

Is the signature checked?

No. That needs the issuer's secret or public key, and you shouldn't paste production keys into a website. This tool only reads the contents; the token is not sent or stored anywhere. The example token is signed with the key secret.

Frequently asked questions

Is the JWT decoder free?

Yes. The JWT decoder is completely free, with no account, sign-up or usage limit.

Is my code stored?

No. Your code is processed in your browser and is not sent to a server or stored.

Does it work on my phone?

Yes. The tool works in any modern browser on a phone, tablet or computer.