JWT Decoder

Decode a JSON Web Token to read its header and payload, with expiry and issue dates. Does not verify signatures.

Decoded token

In short

What is the JWT Decoder?

The JWT decoder splits a JSON Web Token and shows its header and payload as readable JSON, with issue and expiry times converted to dates. It only decodes the token and does not verify the signature, so a decoded token is not proof of authenticity. Decoding runs in your browser.

How to use it

  1. Paste the full token, with its dots, into the box.
  2. Choose whether to show the header, the payload or both.
  3. Read the decoded JSON and the date lines.
  4. Verify the signature separately in your own server code.
Questions

JWT Decoder — FAQ

Does this tool verify the signature?

No. It only decodes. Anyone can create a token with any contents, so always verify signatures on your server with the correct key.

Is it safe to paste a token here?

Decoding happens in your browser and nothing is sent. Even so, avoid pasting live production tokens into any website; use a test token where you can.

Is a JWT encrypted?

A standard signed JWT is only encoded, not encrypted, so its contents are readable by anyone who holds the token. Do not put secrets in it.

More Developer & Web tools