JWT Decoder
Signature not verified
Decoding only reveals the token’s contents. These claims are untrusted: this tool does not verify signatures, issuer, audience, or permissions.
Paste a three-part JWT, optionally prefixed with Bearer. Maximum 100,000 characters.
Your token stays in this page’s memory. It is not uploaded, saved, or added to the URL.
Paste a JWT or load the example to inspect its header and payload.
How it works
Paste a compact JWT to decode its Base64url header and payload locally. An optional Bearer prefix is removed. Copy either JSON section, inspect exp, nbf and iat in UTC and local time, or reset to clear the input. The expiry status updates every second using your device clock.
Example
The unsigned example has sub set to demo and exp set to 1893456000, meaning 1 January 2030 at 00:00 UTC. It becomes expired at that instant. It is only demonstration data, not an authentication credential.
Frequently asked questions
Does decoding verify a JWT signature?
No. Anyone can construct readable claims, including a future expiry. Verification requires an appropriate trusted key, an allowed algorithm, and checks of issuer, audience and application policy. This decoder performs none of those checks.
Which tokens and expiry values are supported?
Three-part compact tokens with JSON objects are supported, including unsigned examples with an empty final segment. Encrypted five-part JWE and nested JWT payloads are unsupported. Time claims must be numbers in Unix seconds, not milliseconds or numeric strings. Missing exp means expiry is unknown, not unlimited validity.