Skip to content
Back

JWT Decoder

Decode a JSON Web Token’s header and payload, check its dates and verify its signature.

Decoded and verified in your browser — the token, secret and key are never sent anywhere.

See what is inside a JSON Web Token

JWT Decoder turns a JSON Web Token back into readable JSON. It shows the header and the payload, lists the standard claims with their dates in your local time and in UTC, and says whether the token has expired, is valid or isn’t valid yet.

If you have the secret or public key, the tool can also check the signature, which tells you whether the token was really issued by that key and hasn’t been edited. Decoding and verification happen in your browser with its built-in Web Crypto functions. The token, secret and key are never sent anywhere.

How to decode and verify a JWT

  1. Paste the token into the box. A leading “Bearer ” and any spaces or line breaks are removed automatically.
  2. Read the status line at the top, then the decoded Header and Payload. Use the copy buttons to take either JSON block.
  3. Check the Registered claims table for the issuer, subject, audience and the three dates.
  4. To verify the signature, look at the algorithm shown under Verify the signature. For HS256, HS384 or HS512 type the shared secret (tick “Secret is base64-encoded” if it is stored that way). For RS, PS and ES algorithms paste the public key in PEM format.
  5. The result appears as soon as the secret or key is entered.

Understanding the status and signature messages

  • Expired … ago: the current time is at or after the exp claim, so servers should reject the token.
  • Valid — expires in …: exp is still in the future. This only describes the dates; it says nothing about the signature.
  • Not valid yet: the nbf (not before) time hasn’t arrived.
  • Signature verified: the header and payload are exactly what the key holder signed.
  • Signature does NOT match: the token was changed, or it was signed with a different secret or key.
  • alg: none: the token is unsigned. Anyone could have written it, so don’t trust its claims.

Why developers decode tokens

  • Debugging sign-in problems: check whether a 401 error comes from an expired token, the wrong audience or a missing claim.
  • Checking what an API receives: see the roles, scopes or user ID your identity provider puts in the payload.
  • Testing your own signing code: confirm that tokens from your backend verify with the key you publish.

How JWTs are put together

Three parts, encoded but not encrypted

A signed JWT is three base64url strings joined by dots: header, payload and signature. Base64url is an encoding, not encryption, so anyone holding the token can read the payload — never put passwords or other secrets in it. Encrypted tokens (JWE) have five parts and can’t be read without the decryption key; the tool recognises them and says so.

Registered claims and dates

iss is the issuer, sub the subject (usually a user ID), aud the intended audience, jti a unique token ID, and exp, nbf and iat the expiry, not-before and issued-at times. The three times are counted in seconds since 1 January 1970 UTC; the tool converts them so you don’t have to. To convert other timestamps, try the Timestamp Converter.

Supported signature algorithms

HMAC: HS256, HS384 and HS512 with a shared secret. RSA: RS256, RS384 and RS512, plus RSA-PSS as PS256, PS384 and PS512. ECDSA: ES256 and ES384. Public keys must be SPKI PEM (BEGIN PUBLIC KEY). Certificates, PKCS#1 keys (BEGIN RSA PUBLIC KEY) and JWK/JWKS keys aren’t accepted, and pasting a private key is refused with an explanation. Other algorithms, such as EdDSA, are reported as unsupported.

JWT Decoder: common questions

Is it safe to paste a real token here?

The page decodes and verifies on your device and makes no network request with the token, secret or key. Still, a live token works like a password until it expires, so treat it with care wherever you paste it, and prefer test tokens when you can.

Why is my token “valid” when the API rejects it?

The status only compares exp and nbf with your device’s clock. An API also checks the signature, issuer, audience, revocation and its own clock, which may differ from yours by a few seconds or minutes.

The payload shows strange characters or an error. Why?

Tokens often get cut off or gain extra characters when copied from logs or emails. The error message names the part that failed — header, payload or signature. Claims with accents or other scripts are decoded as UTF-8 and should display correctly.

Where do I find the public key to verify an RS256 token?

Identity providers publish their keys, usually as a JWKS document. This tool needs the key in PEM format (BEGIN PUBLIC KEY), so convert a JWK to PEM first with your usual tooling.

Can this tool create or edit tokens?

No, it only reads and verifies them. For related tasks, the Base64 Encoder decodes single segments and the JSON Formatter tidies JSON you copy out of a payload.