Skip to content
TinyTools
Developer

JWT Decoder

Decode a JSON Web Token and read its header, payload and expiry.

Result

What is a JWT?

A JSON Web Token consists of three Base64URL parts: header, payload and signature. The payload holds claims such as the user id (sub), issue time (iat) and expiry (exp).

This tool only decodes the content. It does not verify the signature, so never trust a decoded token on its own. Decoding happens in your browser, so tokens are not transmitted.

How to use the JWT Decoder

  1. 1Paste your token.
  2. 2Read header and payload.
  3. 3Check the expiry status.

Frequently asked questions

Does it verify the signature?

No. Verification needs the secret or public key and should happen on your server.

Is it safe to paste a token here?

Decoding runs locally and nothing is sent. Still, avoid sharing live production tokens.

More Developer tools