Developer — Free

Decode a JWT

Header, payload and expiry status at a glance.

  1. 01Paste
  2. 02Adjust
  3. 03Copy
Paste text to begin. Free
01 — Steps

How to decode a JWT

  1. Paste the token

    The three Base64URL parts are split and decoded.

  2. Read the claims

    iat, exp and nbf are shown as dates with an expired flag.

  3. Copy JSON

    Header or payload as formatted JSON.

02 — Questions

Frequently asked questions

Does it verify the signature?
Not yet. It decodes and inspects; signature verification with a public key is on the roadmap.
Why is the payload readable without the secret?
JWTs are signed, not encrypted. Anyone with the token can read its claims.
Does it work with any JWT?
Yes. Any three-part token decodes; the alg header shows which algorithm signed it.
03 — Related
04 — More

More developer tools

All developer tools