Skip to content
ToolShelf

JWT decoder

Split a JSON Web Token into its header and payload, read the claims with the timestamps in plain English, and see when it expires. No signature is verified.

Your token

Your token stays in this tab. The work is done by JavaScript in your browser. None of it is uploaded, logged or saved, and the tool keeps working with the network off.

A Bearer prefix copied from an Authorization header is removed for you.

Decoding is not verifying

The first two parts of a JWT are plain JSON that anyone holding the token can read. This tool reads them. It does not check the signature, so it cannot tell you whether the token is genuine. Anyone can write a payload, base64 it and staple any string on the end.

Verify tokens in your own code, on the server, with a library and a key you control.

Payload

Paste a token and its header and claims appear here.

Decoding is not verifying

A JWT is three base64url segments joined by dots. The first two are ordinary JSON, readable by anyone holding the token, including this page. The third is a signature over them.

This tool reads the first two. That tells you what the token claims. It says nothing about whether those claims are true, because anyone can write a JSON object, base64 it, staple any string on the end and call the result a token. A decoded payload saying {"admin": true} has proved precisely nothing.

Verification is a different operation: recomputing the signature with the issuer’s key and comparing. It needs a key this tool does not have and deliberately never asks for, a web page that collects signing keys is a web page that collects the one secret that matters. Verify in your own code, on the server, with a library.

A JWT is not encrypted

Base64 is an encoding, not a cipher. Anything in a JWT payload is visible to whoever holds the token, and to anyone who finds it in a log file, a browser’s storage or a support ticket. Put nothing in there you would not hand over along with it: no passwords, no secrets, no personal data beyond what the holder is entitled to.

The encrypted variant is a JWE, which has five segments instead of three and genuinely cannot be read without a key. If a token here reports five parts, that is what it is.

The alg: none problem

A token can declare that it has no signature. The original specification allowed it, and it has produced real authentication bypasses: an attacker rewrites the payload, sets alg to none, drops the signature, and any library that trusts the header accepts it.

The lesson generalises. The alg header is part of the unverified data. It is a claim like any other. Verification code should decide which algorithm to expect from its own configuration and reject anything else, rather than asking the token what to do with the token.

Expiry, and the millisecond trap

exp, nbf and iat are NumericDates: seconds since the Unix epoch, not milliseconds. Passing Date.now() straight into one makes it a thousand times too large, which is why tokens sometimes appear to expire in the year 56000. That is shown here as it stands rather than being quietly corrected, because it is a real bug in whatever issued the token.

The expiry status compares the claim against your own computer’s clock. A server may allow clock skew, may not check exp at all, or may simply disagree with your machine, so treat it as what the token says about itself.

Questions

Does this check whether the token is valid?
No. It decodes the header and payload and nothing else. Verifying a JWT means recomputing its signature with the issuer's key and comparing, which needs a key this tool does not have and should never ask for. A decoded token tells you what it claims, not whether those claims are true.
Is a JWT encrypted?
No, and this surprises people. The header and payload are base64url: an encoding with no key, reversible by anyone in a second, as this page demonstrates. Never put anything in a JWT payload that the holder should not read: no passwords, no internal IDs you consider sensitive, no personal data you would not hand over with the token.
Is my token sent anywhere?
No. The decoding runs in JavaScript in your browser, nothing is requested, and no value is logged or stored. Disconnect the network after the page loads and the tool still works. That said, the habit is worth keeping generally: a JWT is often a live credential, and pasting one into a site that does send it somewhere hands over an account.
What does alg: none mean?
That the token carries no signature at all. It was allowed by the original specification for cases where the token is protected some other way, and it has been the root of real authentication bypasses: an attacker rewrites the payload, sets alg to none, drops the signature, and a library that trusts the header accepts it. Any server that accepts alg: none is accepting whatever it is handed.
Why does it say a token has expired when my app still accepts it?
The expiry shown here is read from the exp claim and compared against your computer's clock. A server may allow a small amount of clock skew, may not check exp at all, or may disagree with your clock. It is the token's own claim about itself, which is all a decoder can tell you.
Why is my token's expiry in the year 56000?
Because it was written in milliseconds. A JWT NumericDate is seconds since the Unix epoch, and passing Date.now() straight in makes the value a thousand times too large. This tool shows what the claim actually says rather than guessing at the intent, so a date far in the future is a real bug in whatever issued it.
It says my token has five parts. What is it?
A JWE, an encrypted token rather than a signed one. Its contents genuinely cannot be read without the decryption key, so no decoder can show you the payload. A JWS, the signed kind this tool reads, always has exactly three parts.
Can I edit the payload and re-sign it here?
No, on purpose. Signing needs a secret key, and a web page that collects signing keys is a web page that collects the one secret that matters most. Use a library in your own code, where the key stays on your machine.

More tools