JWT Decoder
Paste a JWT to decode its header and payload, view claims in a readable form, and see human-friendly timestamps for iat, exp and nbf. Decoding only — no secrets required.
Examples
eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjMifQ.xxxx
{ "alg": "HS256" } / { "sub": "123" }How it works
A JSON Web Token is three Base64URL strings joined by dots: header.payload.signature. The decoder splits the token at the dots, decodes the first two parts and shows them as formatted JSON.
- The iat, exp and nbf claims are shown with a readable local date next to the raw number.
- If the token has an exp claim, a banner says whether it has passed, judged by your device’s clock.
The signature is not checked. “Token valid” means only that the expiry time has not passed, not that the token is genuine or untampered. Encrypted tokens (JWE) cannot be read, because their payload is not plain JSON.
How to use JWT Decoder
Why use this tool
Frequently asked questions
No. This tool decodes the token so you can read it. Verifying the signature requires your secret key and should be done server-side.
Decoding happens locally in your browser and nothing is transmitted. Still, treat production tokens with care.
Found a bug or have an idea?
ToolOrbit is actively developed — feedback directly shapes what gets built next.
Send feedback