Skip to main content
QUIETLYTIC
Developer

JWT Decoder

Decode a JSON Web Token and read its header, claims and expiry.

Local · nothing leaves this browser Waiting for token
Esc Clear
Header, claims and checks

Paste a token on the left.

How it works

A JWT is three Base64URL segments separated by dots: a header naming the signing algorithm, a payload of claims, and a signature over the first two. Decoding the first two is arithmetic anyone can do — which is the single most important thing to understand about the format. A JWT is not encrypted. Everything in the payload is readable by anyone holding the token, so nothing secret belongs in one.

Decoding is also not verification. Only a party holding the issuer's signing key can establish that a token is genuine and unmodified. This page never asks for that key and never checks the signature; the third segment is shown verbatim and left alone. Treat every value here as what the token claims, not as fact.

The checks it does run

Structural things that can be judged from the token alone: an alg of none, an empty signature, a missing or already-past exp, an nbf still in the future, a lifetime longer than a day, and an absent aud. Each is reported with its reason rather than a bare score.

Unicode

Segments are decoded to bytes and then read as UTF-8 in strict mode. A payload containing non-ASCII names decodes correctly; a segment that is not valid UTF-8 is reported as an error rather than silently rendered as replacement characters that would look like a successful decode.

Example

A token whose header is {"alg":"none","typ":"JWT"} decodes fine and is flagged immediately: it carries no signature at all, so any server that accepts it is trusting whatever the payload says. That is the classic JWT implementation flaw, and it is visible from the decoded header alone.

Frequently asked questions

Is my token sent anywhere?

No. Decoding is Base64URL and JSON parsing, both of which happen in your own tab. A JWT is a live credential, so this tool makes no network request at all — you can verify that with your browser devtools network panel open.

Why does it say the signature is unverified?

Because it is. Anyone can decode a JWT; only a party holding the signing key can verify one. A decoded payload tells you what the token claims, not whether those claims are trustworthy.

What do exp, iat and nbf mean?

They are Unix timestamps: exp is when the token stops being valid, iat when it was issued, and nbf the earliest time it may be used. Each is shown here as both the raw number and a readable date.

It says my token is malformed — why?

A JWT is three Base64URL segments separated by dots. A missing segment, a stray newline from copying, or standard Base64 padding characters will all fail to parse; the tool reports which of the three segments is at fault.

Related tools

From the intelligence desk