JWT decoder
Decode a JSON Web Token to read its header, payload and time claims. Decoding happens on your device and the token is not sent anywhere. The signature is shown as present or absent but is not verified.
Also known asJWT decode · Decode JWT · Decode JWT token · JWT decoder online · JWT decoder tool
Three small steps.
- Paste the token, with or without the Bearer prefix.
- Choose Decode token.
- Read the header, the payload and the issued, not-before and expiry times.
A few things to know.
Signed tokens (three parts) only; encrypted tokens (five parts) cannot be read without their key. The signature is not verified, so a decoded token is not proof that it is genuine or unaltered. Time claims are shown in your browser's time zone. Treat real tokens as secrets even though this page keeps them on your device.
How your privacy works →A little more clarity.
Does this verify the signature?
No. Verifying needs the secret or public key of whoever issued the token. This tool only decodes the readable parts.
Is it safe to paste a real token?
The token stays in this browser tab and is not transmitted or stored. A token is still a credential, so prefer an expired or test token when you can.
Why can anyone read a token's contents?
A signed token is encoded, not encrypted. Its header and payload are Base64URL text that any holder can decode; the signature only shows whether they were changed.
Related searchesdecode jwt locally · decode jwt token locally · safe jwt decode