Skip to content
Calciyums

JWT Decoder

Show a JWT's header and payload as readable JSON; the signature is not verified.

Developer

Input

Calculated in your browser; what you enter is never sent to a server.

Result

Payload

{
  "sub": "1234567890",
  "name": "John Doe",
  "iat": 1516239022
}
Header
{ "alg": "HS256", "typ": "JWT" }

How does it work?

Paste the JWT into the box. The tool decodes the first two of its three dot-separated parts (the header and the payload) from Base64url and shows them as readable JSON. If the payload has an "exp" claim, it also says whether the token has expired.

Example

{
  "sub": "1234567890",
  "name": "John Doe",
  "iat": 1516239022
}

Similar Tools

Toolbox Get your Toolbox ready.

Star the tools you use most and, with an account, they follow you to every device.

Create account

Frequently asked questions

Does this verify the signature?

No. It only decodes the header and payload into something readable; it doesn't check whether the signature is actually valid. Whether to trust the token is a separate question this tool doesn't answer.

Is my token sent anywhere?

No. Decoding happens entirely in your browser; the token never goes over the network.

What if I paste something with more or fewer than three parts?

The tool says it isn't a valid JWT; a JWT always has exactly three dot-separated parts.

What if there's no "exp" claim?

The expiry line only appears when the payload has an "exp" claim; otherwise you just see the header and payload.