JWT Decoder

Split a token into its three parts, base64url-decode the header and payload, list every claim and tell you whether the time claims look sane. The signature is never checked, and the page says so throughout.

Runs in your browser Developer tools

Decoded, not verified The signature is never checked here, so a readable payload proves nothing about who issued the token.

Demo

Header claims
Claim Value
Payload claims
Claim Value
Payload JSON
Nothing decoded yet.

How to use

  1. Paste the token into the Token box, with or without a leading Bearer prefix; a decode starts as soon as you paste.
  2. Press Decode and read the two tables: Header claims and Payload claims, where exp, iat and nbf also show your local date-time with the zone name and a relative note such as expired 5 minutes ago.
  3. Check the status line for the verdict and the reason it gives, and scroll the Payload JSON pane on the right to see the whole claim set before pressing Copy payload JSON.
  4. No token yet? Press Create a sample token to load a demo whose header says alg none, then Clear to start over.

Frequently asked questions

Does this verify my token?

No, and it cannot. Verification needs the signing secret or public key, and a decoder that accepts a key would encourage the wrong habit. This tool only base64url-decodes the header and payload, which anyone holding the string can do. Use the alg and kid claims to know what algorithm you are supposed to check, then verify the signature in your server with the real key.

Why is my Chinese claim garbled in other decoders?

Because most naive decoders call atob, which yields one character per byte and destroys anything built from multi-byte UTF-8, turning a name such as 张三 into mojibake. Here the decoded bytes are handed to new TextDecoder with utf-8, so CJK claims, emoji and accents come out intact.

What do the exp, iat and nbf verdicts mean?

exp is the expiry instant, iat when the token was issued and nbf the moment it becomes valid. The status line reports ok when exp is still ahead and nbf has passed, err when the token is expired, and warn when there are no time claims to judge, or when exp is missing so the token never expires. All of that is a reading of the numbers, not proof they were signed.

Guides

Related tools