Skip to content
kitbaba

Most used

JWT decoder

Read a JWT's header and payload and check when it expires. Does not verify signatures.

Processed on your device · 0 bytes uploaded

This decodes the token but does not verify its signature. Anyone can make a token with any contents, so don't trust what it says until your server has checked the signature with the right key.

How to use

  1. Paste a JWT into the box. A leading "Bearer " is removed for you.
  2. The header and payload appear below as formatted JSON.
  3. Check the expiry line and the dates for exp, iat and nbf, shown in your local time.
  4. Press Copy above the header or payload to copy it.

Questions

Does this verify the token?

No. It only decodes the header and payload, which anyone can do because they are just Base64URL-encoded JSON. Checking the signature needs the secret or public key and should happen on your server. Never trust a token's contents because they look right here.

Is it safe to paste a real token?

The token is decoded in your browser and never sent anywhere. Still, a live token works like a password until it expires, so be careful where else you paste it.

What do exp, iat and nbf mean?

exp is when the token expires, iat is when it was issued, and nbf is the time before which it must not be accepted. They are stored as seconds since 1 January 1970 (UTC), and shown here in your local time.

Why does it say expired when my server accepts the token?

The status uses your device's clock. If your clock is wrong, or your server allows some clock skew, the two can disagree near the expiry time.

Can it read encrypted tokens?

No. An encrypted JWT (JWE) has five parts instead of three, and its contents can only be read with the decryption key.

Something wrong or missing? Tell us (opens in a new tab)