JWT Decoder
Show a JWT's header and payload as readable JSON; the signature is not verified.
DeveloperResult
Payload
{
"sub": "1234567890",
"name": "John Doe",
"iat": 1516239022
}- Header
- { "alg": "HS256", "typ": "JWT" }
How does it work?
Paste the JWT into the box. The tool decodes the first two of its three dot-separated parts (the header and the payload) from Base64url and shows them as readable JSON. If the payload has an "exp" claim, it also says whether the token has expired.
Example
{
"sub": "1234567890",
"name": "John Doe",
"iat": 1516239022
}Similar Tools
Toolbox Get your Toolbox ready.
Star the tools you use most and, with an account, they follow you to every device.
Frequently asked questions
Does this verify the signature?
No. It only decodes the header and payload into something readable; it doesn't check whether the signature is actually valid. Whether to trust the token is a separate question this tool doesn't answer.
Is my token sent anywhere?
No. Decoding happens entirely in your browser; the token never goes over the network.
What if I paste something with more or fewer than three parts?
The tool says it isn't a valid JWT; a JWT always has exactly three dot-separated parts.
What if there's no "exp" claim?
The expiry line only appears when the payload has an "exp" claim; otherwise you just see the header and payload.