🏠 Home
CPS Test Aim Trainer Typing Speed Scroll Speed View All Games →
AI Image Generator Background Remover Social Media Cropper Youtube Thumbnails View All Images →
Word Counter Case Converter Invisible Text Text to Speech View All Text Tools →
JSON Formatter Diff Checker Base64 Converter Meta Tag Generator View All Dev Tools →
Unit Converter Age Calculator BMI Calculator Time Zone Converter View All Calculators →
Home > JWT Decoder

JWT Decoder

Decode any JSON Web Token: header, claims, expiry status. Private.

Decoded token appears here.

Share This Tool

Free Online JWT Decoder — Header, Payload & Expiry

JSON Web Tokens carry identity between services as three base64url-encoded segments: header.payload.signature. Debugging auth means constantly peeking inside them. This free decoder splits any JWT, decodes the header and payload with full Unicode support, tabulates every claim, translates exp/iat/nbf timestamps into dates with live expired/valid badges, and reports signature presence — all client-side.

How to Decode a Token

  1. Paste the full token — copy from DevTools, logs, or your Authorization header, all three dot-separated parts.
  2. Click Decode — header shows algorithm and type; the claims table lists every field with plain-English meanings for standard claims.
  3. Check expiry — the exp row shows a live EXPIRED badge or remaining hours, computed against your clock.

Understanding JWT Structure

The header declares the signing algorithm (HS256, RS256, ES256) and token type. The payload holds claims: registered ones (iss issuer, sub subject, aud audience, exp/iat/nbf timestamps) plus any custom fields your auth server adds. The signature proves integrity — but verification requires the secret or public key, which must happen on a server, never in a browser tool. Treat pasted tokens as compromised afterwards if they grant real access: rotate them.

Why does my token show as expired?

Compare the exp date against the current time, then check clock skew: test environments often issue short-lived tokens (minutes), and a machine clock minutes off can falsely expire them.

Is pasting tokens here safe?

Decoding is fully local — nothing transmits. But any token that authorizes real resources should be considered exposed once pasted anywhere; prefer short-lived test tokens and rotate production ones after debugging.

What is base64url?

Standard Base64 with +// swapped for -/_ and padding omitted, making tokens URL-safe. The decoder reverses the swap and restores padding automatically.

Related Tools

Validate API payloads with the JSON Formatter, encode secrets with the Base64 Converter, and convert timestamps with the Timestamp Converter.

⭐
Enjoying NoLoginTool?

Save it for later access 🚀