Skip to content
EN
English 简体中文 soon 日本語 soon
Run here 100% in your browser, no upload, no login

JWT Decoder

Decode JWT header and payload locally, read exp and iat as human dates. Signature not verified.

Header

—

Payload

—

Signature(not verified — decode only)

Warning: decoding does not verify a token. Never trust payload claims from an untrusted source without signature verification on your server.

How to use it

  1. Paste a JWT (the eyJ… string with three dot-separated parts).
  2. The header and payload are decoded and pretty-printed instantly.
  3. Registered claims such as exp and iat are shown as human-readable dates with an expiry warning when a token has lapsed.

Common use cases

FAQ

Q: Does this tool verify the signature? A: No, and it says so clearly. Decoding shows the claims, but anyone can forge unsigned claims. Signature verification must happen on your server with the correct secret or public key.

Q: Is the token safe to paste? A: This page never transmits anything, but a JWT in the wild may already be readable by anyone who holds it. Treat paste-sensitive tokens as you would any credential.

Q: Why is my token "invalid"? A: Check that it is a complete JWT with exactly three parts. Refresh tokens in opaque formats (like random hex) are not JWTs and cannot be decoded.

Used in these workflows

Your data stays on this device

JWT Decoder runs 100% locally. Everything you paste or drop is processed by your own browser and never transmitted. Nothing is stored on our servers — close the tab and it is gone.

Nothing you type is sent to a server, logged, or used for analytics. The page works even with your network disconnected after first load.