TTKTheTextKit
Developer & Web Tools

JWT Decoder

Paste a JSON Web Token to read its header and payload, see the times in its exp, nbf and iat claims, and find out whether it has expired. The token is decoded in your browser and is not uploaded. This tool does not verify the signature.

Decoding happens in your browser and the token is not uploaded. Treat a live token like a password anyway, and prefer an expired or test one.

Related Tools

[4 suggestions]

About the JWT Decoder

A JSON Web Token in its common form has three parts separated by dots: a header, a payload and a signature. The header and payload are JSON objects written in base64url, the URL-safe form of Base64, and RFC 7519 defines the claims inside the payload. This tool reverses that encoding and shows the JSON. It also reads the registered claims: iss for the issuer, sub for the subject, aud for the audience, exp for the expiration time, nbf for not before, iat for issued at and jti for the token ID. Times in a JWT are in seconds since 1970, and the tool converts them to UTC dates. It tells you whether the token is inside its time window right now, using the rule that a token must not be accepted on or after its exp time and not before its nbf time. It warns about an algorithm of none, which means the token is unsigned, about a missing exp, about times that look like milliseconds, and about a malformed signature part. Two points matter more than any warning. First, decoding is not verifying: the signature is never checked here, so a decoded token proves nothing about who made it. Second, a normal JWT is encoded, not encrypted, so anyone who holds the token can read what is inside it. A token with five parts is an encrypted JWE, and its contents cannot be read without the key.

Does this tool verify the signature?▾

No. It only decodes the header and payload. Verifying needs the secret or public key and must be done by your server or a trusted library. A token that decodes cleanly can still be forged.

Is it safe to paste a token here?▾

The token is decoded in your browser and not sent anywhere. Still, a live token works like a password until it expires, so prefer a test or expired token, and never paste one into a site you do not trust.

Can anyone read the contents of a JWT?▾

Yes. A normal signed JWT is only encoded in base64url, not encrypted, so anyone who has the token can read the payload. Do not put secrets in it. An encrypted token (JWE) has five parts.

What are exp, nbf and iat?▾

They are times in seconds since 1970. The exp claim is when the token stops being valid, nbf is when it starts being valid, and iat is when it was issued. The decoder shows each as a UTC date.