# JWT Decoder

URL: https://tools.otaku-dojo.com/en/jwt-decoder
Updated: 2026-10-03

The JWT Decoder splits a JSON Web Token into its parts, decodes the header (algorithm) and payload (user data and claims), converts exp, iat and nbf timestamps into dates and tells you whether the token has expired. Decoding happens only in your browser and the token is never sent anywhere. The signature is not verified.

## How to use the JWT Decoder

1. Paste a JWT on the left (a leading "Bearer " is fine), or press "Sample".
2. The right side shows the algorithm, expiry status and the header and payload JSON.
3. Review issuer, subject and expiry in the "Registered claims" table.
4. Press "Copy" to copy the formatted payload JSON.

## Specs & key facts

- **Standards**: RFC 7519 (JWT), RFC 7515 (JWS)
- **Decodes**: Header, payload and registered claims (iss, sub, aud, exp, nbf, iat, jti)
- **Times**: exp / iat / nbf shown as local time and relative time
- **Signature**: Not verified (requires a key — verify on your server)
- **Processing**: In your browser (the token is never uploaded)
- **Price**: Free, no sign-up

## Examples: Decode an HS256 token

```text
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0IiwibmFtZSI6Ik90YWt1IiwiaWF0IjoxNzU5NDYwMDAwfQ.sig
```

→

```text
Header:  {"alg": "HS256", "typ": "JWT"}
Payload: {"sub": "1234", "name": "Otaku", "iat": 1759460000}
```

## FAQ

### Is it safe to paste a production JWT?

Decoding happens entirely in your browser and the token is never transmitted or stored. Still, a JWT is effectively a login credential, so only do this on a trusted computer and clear it afterwards.

### Why doesn't it verify the signature?

Verifying HS256 needs the shared secret and RS256 needs the public key. Pasting secrets into a web page risks leaking them, so verification belongs in your backend.

### Which time zone is the exp time shown in?

exp, iat and nbf are Unix seconds in UTC; the tool converts them to your browser's time zone.

### What does "looks like an encrypted JWE" mean?

A five-part token is a JWE (encrypted JWT). Its payload is encrypted and cannot be read without the decryption key.
