Decode a JSON web token.

Paste a JWT and see its header and payload decoded and readable, instantly and privately.

  • 3 claimsexp, iat and nbf read as dates
  • Bearerprefix and line breaks stripped
  • Localthe token never leaves the page
JWT decoderRuns in your browser

Loading the tool…

How it works

From a raw token to readable claims in three steps.

  1. Paste the token

    Paste it straight from an Authorization header or a log. The Bearer prefix and any line breaks come off.

  2. Read the header and payload

    Both print as indented JSON with a Copy button each. The header's alg field names the signing algorithm.

  3. Check the times

    exp, iat and nbf show as dates in your local time, with expired or not expired beside exp.

In the decoder

What the JWT decoder does.

  • Decodes as you paste

    The header and payload appear with every change.

  • Header as JSON

    Indented, with its own Copy button.

  • Payload as JSON

    Indented, with its own Copy button.

  • Readable times

    exp, iat and nbf as dates in your local time.

  • Expiry state

    expired or not expired, judged by your computer's clock.

  • Not-before state

    in effect or not valid yet, for nbf.

  • Bearer removed

    The prefix comes off in any capitalisation.

  • Line breaks removed

    A token wrapped across lines still reads.

  • Signature shown

    Printed as it is in the token, never checked.

  • JWE spotted

    A five-part token is named as encrypted, not misread.

  • Named errors

    A bad segment is named, header or payload.

  • Stays in the page

    The token is never sent anywhere.

What you see

A token beside what it says.

The token's three parts on one side. On the other, its expiry and issue times as dates, then the header and payload as indented JSON. This one has expired, so the line under exp says so.

  • Header and payload as JSON
  • Expiry shown as a date
  • The signature is never checked

JSON web tokens

Why decode tokens here.

A JWT is three base64url segments joined by dots, and none of them can be read as it stands. The decoder above accepts a token straight from an Authorization header or a log line and prints the header and payload as indented JSON. For Base64 outside a token, the plain Base64 converter handles text and files.

The signature is printed as it appears and never checked, because that needs the signing secret or public key, which belong on your server. To hand a decoded payload to a teammate, save it as a .json file and share it as a JSON link instead of pasting the claims into a chat.

The decoder is free and needs no account. A link made without an account lasts 7 days, and signing up for the Free plan keeps it until you delete it.

Frequently asked questions

  • Is it safe to paste a token here?

    The token is decoded in this page, and nothing here sends or stores it. A production token is still a live credential, so use an expired or test token when you can.

  • Does this verify the signature?

    No. The signature is shown without being checked. Verification needs the signing secret or public key, and that belongs on your server.

  • Why does my token show as expired?

    The decoder compares the exp claim with the clock on your computer. If that time has passed, the token shows as expired. A token without exp shows no expiry.

  • Is the JWT decoder free?

    Yes. Decoding needs no account and costs nothing, and there is no limit on how many tokens you read.

  • Do I need to remove the Bearer prefix?

    No. The decoder takes Bearer off the front, in any capitalisation, and removes spaces and line breaks, so a token copied from a header or a wrapped log line reads as it is.

  • Which time claims does it read?

    exp, iat and nbf, when they are numbers. Each shows as a date in your local time. exp says expired or not expired, nbf says in effect or not valid yet, and iat shows the date alone.

  • What if the token has five parts?

    Five segments mean an encrypted JWE, and the decoder says so rather than trying to read it. Decrypting one needs the key it was encrypted with.

  • Why does it say a segment is not valid base64url?

    The header or payload holds a character outside the base64url alphabet, or has the wrong length, which usually means part of the token was lost in copying. The message names the segment that failed.

  • What if a segment is not JSON?

    A JWT's header and payload are JSON objects. If one decodes to something else, the decoder says that segment is not valid JSON rather than guessing at it.

  • Can I copy the decoded parts?

    Yes. The header and the payload each have a Copy button that puts the indented JSON on your clipboard.

  • Is the payload secret?

    No. A signed JWT's payload is only encoded, so anyone who has the token can read it, as this page shows. Keep secrets out of the claims, or use an encrypted token.

  • Does the decoder keep my token?

    No. The token lives in this page while it is open, and nothing is saved in the browser or sent anywhere.

  • Why does nbf say not valid yet?

    The token's not-before time is still in the future by your computer's clock, so a server checking it would refuse the token until then. If your clock is wrong, the line is wrong too.

  • Which signing algorithms does it read?

    Any. The decoder reads the header whatever alg it names, such as HS256, RS256 or ES256, because decoding does not depend on the algorithm. Only verifying the signature would.

  • Can I decode an ID token or an access token?

    Yes, when it is a JWT. OpenID Connect ID tokens are JWTs, and many access tokens are too. An opaque token, a random string with no dots, is not a JWT and gets a message that it has the wrong number of segments.

  • Why do the times look hours off?

    They are shown in your local time zone, while the token stores seconds since 1 January 1970 in UTC. Someone in another time zone sees the same moment as a different clock time.

  • Can I edit the token here?

    No. The decoder reads a token and shows what it says. Changing a claim would need a new signature from the key that signed it.

  • What about a token with alg set to none?

    A token whose header says none carries no signature, and the decoder shows None on this token in its place. Servers should refuse such a token unless they were set up to expect one.

  • Can I read the signature?

    It is shown as the base64url text from the token. That text is the signature's bytes, not something that decodes to readable words.

  • Does it cope with a large payload?

    Yes. The header and payload boxes scroll, so a long payload stays readable, and each has a Copy button for the full JSON.

  • What is a JWT used for?

    Carrying claims about a user or a session between services, most often in an Authorization header. The server that receives one checks the signature before it trusts any claim.

  • What does the typ field mean?

    It names the kind of token, usually JWT. The decoder shows it with the rest of the header and does not rely on it.

  • What if exp is a string rather than a number?

    Only numeric time claims get a row, since the standard stores them as seconds. A claim written as a string shows in the payload JSON but gets no date line.

Get file-sharing tips that actually help.

One email a month. No spam, no fluff.

Ready to try the dev tools?

Free forever, no credit card needed. The whole thing takes a few seconds.

Get started free