Skip to content

Pedro Ivotools

JWT Decoder

Decode a JSON Web Token to read its header, payload and expiry dates, locally. The signature is shown but never verified or sent.

Local calculation
The result is calculated in your browser.
Private by default
Nothing you enter leaves your browser.

How it works

A JWT is three Base64URL-encoded parts separated by dots. The header and payload are decoded as JSON, and the iat, nbf and exp claims are shown as readable dates.

Decoding does not prove the token is genuine: only the issuer's key can verify the signature. Because tokens often grant access, this tool never sends them anywhere.

Questions

Is it safe to paste a real token here?

The token is decoded in your browser and never transmitted or stored. Still, treat live tokens like passwords and prefer expired or test tokens when you only need to inspect the format.

  • Base64 Encoder and Decoder

    Encode text to Base64 or decode Base64 back to text, with full UTF-8 support. Runs entirely in your browser.

  • JSON Formatter

    Format, validate and minify JSON in your browser. Pretty-print with your choice of indentation or compact it to one line.

  • Unix Timestamp Converter

    Convert Unix timestamps in seconds or milliseconds to readable dates, and dates back to timestamps, in UTC and your local time zone.

Esc