How to use the JWT Decoder
- Paste a JWT on the left (a leading "Bearer " is fine), or press "Sample".
- The right side shows the algorithm, expiry status and the header and payload JSON.
- Review issuer, subject and expiry in the "Registered claims" table.
- Press "Copy" to copy the formatted payload JSON.
Examples
Decode an HS256 token
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0IiwibmFtZSI6Ik90YWt1IiwiaWF0IjoxNzU5NDYwMDAwfQ.sig
Header: {"alg": "HS256", "typ": "JWT"}
Payload: {"sub": "1234", "name": "Otaku", "iat": 1759460000}
How a JWT is structured
A JWT is three Base64URL strings joined by dots: the header names the signing algorithm (such as HS256 or RS256), the payload holds user data and claims, and the signature is produced by the server from the first two parts using a secret key.
The payload is encoded, not encrypted — anyone holding the token can read it — so never put passwords or sensitive personal data in a JWT.
Specs & key facts
| Standards | RFC 7519 (JWT), RFC 7515 (JWS) |
|---|---|
| Decodes | Header, payload and registered claims (iss, sub, aud, exp, nbf, iat, jti) |
| Times | exp / iat / nbf shown as local time and relative time |
| Signature | Not verified (requires a key — verify on your server) |
| Processing | In your browser (the token is never uploaded) |
| Price | Free, no sign-up |
FAQ
Is it safe to paste a production JWT?
Decoding happens entirely in your browser and the token is never transmitted or stored. Still, a JWT is effectively a login credential, so only do this on a trusted computer and clear it afterwards.
Why doesn't it verify the signature?
Verifying HS256 needs the shared secret and RS256 needs the public key. Pasting secrets into a web page risks leaking them, so verification belongs in your backend.
Which time zone is the exp time shown in?
exp, iat and nbf are Unix seconds in UTC; the tool converts them to your browser's time zone.
What does "looks like an encrypted JWE" mean?
A five-part token is a JWE (encrypted JWT). Its payload is encrypted and cannot be read without the decryption key.