Decode a JWT
Header, payload and expiry status at a glance.
- 01Paste
- 02Adjust
- 03Copy
Paste text to begin. Free
01 — Steps
How to decode a JWT
- Paste the token
The three Base64URL parts are split and decoded.
- Read the claims
iat, exp and nbf are shown as dates with an expired flag.
- Copy JSON
Header or payload as formatted JSON.
02 — Questions
Frequently asked questions
Does it verify the signature?
Not yet. It decodes and inspects; signature verification with a public key is on the roadmap.
Why is the payload readable without the secret?
JWTs are signed, not encrypted. Anyone with the token can read its claims.
Does it work with any JWT?
Yes. Any three-part token decodes; the alg header shows which algorithm signed it.
03 — Related
Related tools
04 — More
All developer tools