JWT Decoder
Decode a JSON Web Token to read its header, payload and expiry dates, locally. The signature is shown but never verified or sent.
- Local calculation
- The result is calculated in your browser.
- Private by default
- Nothing you enter leaves your browser.
How it works
A JWT is three Base64URL-encoded parts separated by dots. The header and payload are decoded as JSON, and the iat, nbf and exp claims are shown as readable dates.
Decoding does not prove the token is genuine: only the issuer's key can verify the signature. Because tokens often grant access, this tool never sends them anywhere.
Questions
Is it safe to paste a real token here?
The token is decoded in your browser and never transmitted or stored. Still, treat live tokens like passwords and prefer expired or test tokens when you only need to inspect the format.
Related tools
Base64 Encoder and Decoder
Encode text to Base64 or decode Base64 back to text, with full UTF-8 support. Runs entirely in your browser.
JSON Formatter
Format, validate and minify JSON in your browser. Pretty-print with your choice of indentation or compact it to one line.
Unix Timestamp Converter
Convert Unix timestamps in seconds or milliseconds to readable dates, and dates back to timestamps, in UTC and your local time zone.