JWT Decoder — Decode & Verify JSON Web Tokens Online
Decode a JWT's header and payload, read the expiry in plain language, and verify an HMAC signature. Tokens never leave your browser.
{
"alg": "HS256",
"typ": "JWT"
}{
"sub": "user_42",
"name": "Ada Lovelace",
"role": "admin",
"iat": 1757320000,
"exp": 1788856000
}| sub | Subject | user_42 |
| name | Ada Lovelace | |
| role | admin | |
| iat | Issued at | 1757320000 |
| exp | Expires | 1788856000 |
Decoding never checks the signature. Anyone can read a JWT; only the signature proves who issued it. The secret stays in your browser.
Tokens are decoded in your browser and never sent anywhere; still, treat a pasted production token as a credential. Designing authentication, sessions or API access for a product? We do that securely.
Found a problem, or something that could be better? We read every message and we fix things quickly.
This free JWT decoder shows the header, payload and claims of a JSON Web Token, turns exp, iat and nbf into readable dates with a clear valid or expired verdict, and can verify HMAC-signed tokens against a secret. Everything happens in your browser, which matters here more than for most tools: a pasted token is often a live credential, and it should not be sent to anyone's server, including ours.
A JWT is three Base64URL sections separated by dots: a header naming the algorithm, a payload of claims, and a signature. The first two are not encrypted, only encoded, so anyone can read them; the signature is what proves who issued the token and that it was not altered. Decoding is therefore not the same as trusting, and the page keeps that distinction visible.
How to use
- Paste the token. A leading “Bearer ” from an Authorization header is fine; it is stripped.
- Read the status line: valid for how long, expired since when, or not yet valid.
- Check the payload and the claims table. Time claims are shown as local dates alongside the raw Unix seconds.
- To verify an HMAC-signed token (alg HS256, HS384 or HS512), enter the shared secret and press Verify. RS256 and ES256 tokens need the issuer's public key and are not verified here.
- Copy the payload or header as formatted JSON if you need it in a bug report or a test fixture.
Frequently asked questions
Is it safe to paste a real token here?
The token is decoded with JavaScript in your browser and is never transmitted; you can disconnect from the internet and the page keeps working. That said, treat a production token like a password: do not paste it into any page you do not trust, and prefer a short-lived test token when you can.
Why can I read the payload without the secret?
Because JWTs are signed, not encrypted. The payload is Base64URL-encoded JSON that anyone can decode. The secret (or private key) is only needed to create or verify the signature. Never put sensitive data in a JWT payload unless you are using JWE, the encrypted variant, which this tool does not decode.
What do exp, iat and nbf mean?
They are Unix timestamps in seconds. exp is when the token expires; iat is when it was issued; nbf (not before) is the earliest moment it is valid. A verifier must reject a token after exp or before nbf. The status line here applies both rules to the current time.
Why does verification say “cannot verify” for my token?
The token is signed with an asymmetric algorithm (RS256, ES256, PS256) that needs the issuer's public key, usually published at a JWKS URL. This tool verifies only HMAC algorithms, where the secret is shared. Asymmetric verification is possible in the browser but needs the key, and most people testing a token do not have it to hand.
What does “alg: none” mean and why the warning?
It declares the token has no signature. Some libraries historically accepted such tokens as valid, which let attackers forge any payload. A properly configured verifier rejects alg none outright. If you see it in a real system, that is a security finding, not a curiosity.
Anatomy of a JWT
Header: {"alg":"HS256","typ":"JWT"} tells the verifier which algorithm signed the token. Payload: the claims, a JSON object of whatever the issuer chose to include, plus the registered claims (iss, sub, aud, exp, nbf, iat, jti) that verifiers understand. Signature: HMAC or a digital signature over base64url(header).base64url(payload). Change one character of the payload and the signature no longer matches, which is the whole point.
Common JWT mistakes
• Trusting the payload without verifying the signature, or verifying with the algorithm named in the token rather than the one the server expects (algorithm confusion).
• Long-lived access tokens. Keep exp short (minutes to an hour) and use a refresh token for longer sessions.
• Putting personal or secret data in the payload; it is readable by anyone who holds the token.
• Storing tokens in localStorage on a site with any XSS exposure. An httpOnly cookie is safer for browser sessions.
• Forgetting to check aud and iss, which lets a token issued for one service be replayed against another.
Related free tools
- Base64 Encoder / Decoder — Encode text or files to Base64 and decode back, with correct UTF-8 handling and data-URL output. Nothing leaves your browser.
- JSON Formatter — Pretty-print, minify and validate JSON, with parse errors located by line and column. In your browser, no upload.
- Password Generator — Generate a strong random password, a memorable passphrase or a PIN. Runs entirely in your browser, nothing is sent or stored.