JWT Decoder

Header / Payload / Signature with expiry check

🔒 See this tool’s privacy notes for local processing and external service details. Site analytics are described in our privacy policy.
Header
—
Payload
—
Signature
—

Decodes only — does not verify signature.

Quick guide

What can JWT Decoder help you do?

Free JWT decoder. Shows header, payload, signature, and expiry status. Browser-only — your token stays private.

Best for

Inspect a JWT Header, Payload, and Signature during API or OAuth debugging, and convert iat and exp to dates. Decoding cannot prove validity.

How to use it

Paste a JWT with three dot-separated parts. Header and Payload show JSON; Signature stays encoded, while iat and exp show timing details.

How to read the result

Valid only means exp has not passed and parsing worked; Signature was not verified. Device time affects displayed dates.

Privacy and limits

Decoding stays in your browser. Never paste a production access token, session cookie, or unredacted personal claims.

Signature, alg, iss, aud, and revocation are not verified. Enforce algorithms and keys server-side.

Frequently Asked Questions

What is a JWT?

JSON Web Token — three Base64-encoded parts used for API auth and sessions.

Does this verify signatures?

No — verification requires the secret key from your server.