JWT Decoder

Read the header, claims and expiry of a JSON Web Token in your browser. Decoding only — no signature is verified.

Runs entirely in your browser. Nothing is uploaded, logged or stored.

This decodes. It does not verify. Nothing below tells you whether the token is genuine. Anyone holding a signed token can read its claims, and anyone can write a token that looks like this one. Check the signature in your application, with your key.

Three parts separated by dots. Nothing is sent anywhere.

Paste a token and see its header, its claims and its expiry. The decoding happens in your browser: the token is not sent, logged or stored.

This tool does not check the signature, and nothing it shows you means the token is genuine.

How it works

A JSON Web Token is three base64url-encoded parts separated by dots: a header saying which algorithm signed it, a payload of claims, and a signature over the first two. The first two are encoded, not encrypted — anyone holding the token can read them, which is exactly what happens here.

The registered time claims are shown as readable dates: `exp` when it stops being valid, `nbf` when it starts, `iat` when it was issued. Those are compared against your clock to say where the token sits in its window.

The signature is shown as it was written and is not decoded. It is a signature over bytes, not text, and rendering it as characters would suggest it says something.

Examples

Case Input Result
A token that declares no signature eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.eyJzdWIiOiIxMjM0NTY3ODkwIn0. alg none, typ JWT, sub 1234567890

Frequently asked questions

Why does it not verify the signature?

Because verifying needs the signing key, and a page that asked for it would be asking you to paste the secret protecting your system into a website. There is also a subtler reason: a decoder that looked like it verified would invite you to trust a payload anyone could have written. Verify in your application, with your key.

Is a JWT encrypted?

No. A signed token is encoded, which is not the same thing: anyone who holds it can read every claim in it, no key required. Never put anything in a token that the bearer should not see. Encrypted tokens exist — they have five parts rather than three — and this tool cannot read those.

What does an algorithm of "none" mean?

That the token carries no signature at all. It is the oldest attack against JWT: strip the signature, set `alg` to `none`, and hope the receiving library accepts it. The page flags such a token; if you are seeing one you did not create, treat it as hostile.

Does my token leave the browser?

No. Decoding runs locally in JavaScript, and there is no share link for this tool, because a link would put the token in a URL — where it would land in browser history and server logs.

Good to know

  • Decoding only. No signature is verified, and nothing on this page says whether a token is genuine.
  • The token is decoded in your browser and is never sent, logged or stored. The tool needs JavaScript; without it there is no decoding at all.
  • A signed token is readable by anyone holding it. Treat every claim in one as public.

Sources

All Code tools