JWT Decoder
Read the header, claims and expiry of a JSON Web Token — without sending it anywhere.
Runs entirely in your browser
Loading tool...
How to use
- Paste a JSON Web Token. A leading "Bearer " is fine — it is stripped.
- Read the header, the registered claims, and anything else the token carries.
- Check the expiry, which is shown as a date and as a relative time.
- Note the warnings: an expired token, a missing expiry, or alg none all change how the token should be treated.
Features
- Header, registered claims and custom claims, separated rather than dumped as one blob.
- Expiry, not-before and issued-at resolved from seconds into readable dates.
- Warns about expired tokens, missing expiry, alg none and tokens that live longer than a month.
- Correct on non-ASCII claims — a name with a diacritic decodes as UTF-8, not as bytes.
- Never transmitted or stored: a valid token is a working credential.
Frequently asked questions
- Does this verify the token?
- No, and no browser tool honestly can. Verifying means recomputing the signature with the signing secret, and that secret belongs on your server — pasting it into a web page would hand it over. This decodes, which needs no key at all, and says so rather than implying a check it has not done.
- If anyone can read it, is a JWT encrypted?
- No. The payload is base64url-encoded, which is an encoding, not encryption — anyone holding the token can read every claim in it. A signature proves the contents were not altered; it does not hide them. Never put anything in a JWT you would not put on a postcard.
- Is it safe to paste a real token here?
- Here, yes: the decoding happens in the page and the token is never transmitted or stored. Be careful in general, though — a token that has not expired is a working credential, and most online decoders send it to a server. Prefer an expired token when you can.
- What does alg: none mean?
- That the token is unsigned and asserts nothing about who issued it. It exists in the specification for cases where integrity is guaranteed some other way, and it has been the basis of real authentication bypasses where a server trusted the header's own claim about which algorithm to use. If you see it on a token that is meant to be trusted, that is a finding.
Related tools
Sign a test token, or check whether one was really signed with your secret.
Convert text to Base64 and back again.
Generate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes, or verify a checksum.
Format and beautify JSON instantly.