◪ DEVELOPER Updated July 25, 2026
JWT Decoder
Inspect a JWT's header, payload, and expiry.
JSON Web Token
—Algorithm
—Status
—Expires
Header
Payload
Ad space · belowTool · horizontal
How it works
A JWT is three Base64URL segments joined by dots. The decoder splits on the dots, Base64URL-decodes the header and payload, pretty-prints the JSON, and turns the standard iat, nbf, and exp timestamps into readable dates so you can see at a glance whether the token is still valid.
Frequently asked questions
Does this verify the signature?
No. Verification needs the signing secret or public key, which should never leave your server. This tool only decodes the readable header and payload.
Is my token sent to a server?
No. Decoding happens entirely in your browser, so the token never leaves your device. Still, treat any live token as a credential.
Comments