Skip to main content
eyunzhu

JWT decoder

Inspect a JWT header and payload separately, and read issued-at, not-before and expiry claims as UTC dates.

Decoded only. The signature has not been verified; these claims do not establish trust or validity.

Updates as you type or change an option

Header

Payload

Processed in this browser. Nothing is uploaded or saved.

About this tool

Inspect token fields while debugging an API. A readable payload is useful evidence about the contents, but it cannot establish that the token is trusted.

How to use

Paste a JWT with three dot-separated parts. The header and payload are formatted as JSON and can be copied separately. Numeric iat, nbf and exp claims also appear as UTC dates.

This tool does not verify the signature, issuer, audience or revocation status. Anyone can alter unverified claims, so the display does not establish that a token is trusted or valid. Tokens remain in page memory. Input limit: 128 KiB.

Common questions

Does successful decoding mean the JWT signature is valid?

No. Signatures, issuer, audience and revocation are not checked. Claims can be forged. This tool reads three-part JWTs; it does not decrypt five-part JWE tokens.

Should I paste the whole Authorization header?

Paste only the token, without Bearer or the header name. It must have three dot-separated parts and fit within 128 KiB. The token is processed in the page, without uploading it.

How do I read iat, nbf and exp?

They mean issued at, not valid before and expires at. Numeric values are interpreted as Unix seconds and shown in UTC; a displayed date does not verify that the claim is trustworthy.

Comments

0
to join the discussion.
No comments yet.
Reply thread

Follow the complete conversation chronologically; each reply identifies the specific message it answers.