JWT Decoder

Input

Emptyheader.payload.signature

Decoded token

Paste a JWT to see its header, payload, and signature.

Expiry unknownsignature not verified

About this JWT Decoder

Decode, inspect, and optionally verify a JWT's signature in your browser — HS/RS/ES up to 512-bit.

Decoding happens locally as you type — the token is never uploaded. The expiry and not-before badges read theexp/nbfclaims against your device clock. Signature verification is opt-in: enter the secret (for HS256/384/512) or the public key in PEM form (for RS256/384/512 and ES256/384/512) and the badge updates to confirm whether the signature is genuine — until a key is entered, an unexpired token is not evidence that the token is authentic.

FAQ

Is decoding a JWT the same as verifying it?

No. Decoding just reads the Base64URL-encoded header and payload — anyone can do that without a key. Verifying checks the signature against a secret or public key to confirm the token wasn't tampered with. This tool does both: paste a token to decode it instantly, then optionally add the secret (HS256/384/512) or public key in PEM form (RS256/384/512, ES256/384/512) to verify the signature too.

Can anyone read my JWT's payload without the secret key?

Yes — the header and payload are only encoded, not encrypted. Never put sensitive data (passwords, SSNs) in a JWT payload; assume anyone holding the token can read its contents.

Why does my token look invalid or fail to decode?

A valid JWT has exactly three Base64URL-encoded parts separated by dots. Check for truncation from a copy-paste, stray whitespace, or a string that isn't a JWT at all.

What do exp, iat, and nbf mean?

Standard timestamp claims — exp (expiration), iat (issued at), nbf (not before) — usually in Unix time. Paste the number into the Timestamp Converter to read it as a real date.

Does this tool send my token anywhere?

No — decoding and verification both run entirely client-side. That matters more here than almost anywhere else on this site: a JWT is often a live session credential, and pasting one into a server-side decoder means trusting that server with your session.

Can I edit the decoded payload and re-encode it?

No — this tool is read-only by design: decode and verify only, nothing gets re-signed here. To build a token with custom claims from scratch, use the JWT Generator.

Related tools