JWT Decoder

Runs in your browserDeveloper Tools#Security#Auth

Decode JWTs to read claims and expiry, and check HS256 signatures, without sending the token anywhere.

alg: HS256typ: JWT Not expired: expires in 1 hour

Decoding is not verification. Anyone can read a JWT and change its contents. Only a signature check with the right key shows that it is genuine.

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c2VyXzgyMzEiLCJuYW1lIjoiQXNoYSBWZXJtYSIsImVtYWlsIjoiYXNoYUBleGFtcGxlLmluIiwicm9sZSI6ImFkbWluIiwiaWF0IjoxNzkxMzk3MTkzLCJleHAiOjE3OTE0MDEwOTN9.pdRXlsCYHX8bm7MSZPUtYC5v5gY6Vyx6S2WErtNE8sI

HeaderPayloadSignature

Header

{
  "alg": "HS256",
  "typ": "JWT"
}

Payload

{
  "sub": "user_8231",
  "name": "Asha Verma",
  "email": "asha@example.in",
  "role": "admin",
  "iat": 1791397193,
  "exp": 1791401093
}

Claims

ClaimValue
subSubjectuser_8231
nameNameAsha Verma
emailEmailasha@example.in
roleRoleadmin
iatIssued at17913971937 Oct 2026, 11:49:53 pm IST5 minutes ago
expExpires17914010938 Oct 2026, 12:54:53 am ISTin 1 hour

Signature

pdRXlsCYHX8bm7MSZPUtYC5v5gY6Vyx6S2WErtNE8sI

The secret stays on this page. Never paste a production secret on a shared computer.

Signature verified with this secret (HS256).

How to use, limits & privacy

About JWT Decoder

Decode a JSON Web Token (JWT) to read its header and claims. Times such as exp and iat are shown in IST and your own time, with a clear "expired 3 hours ago" style status. For HS256, HS384 and HS512 tokens you can also check the signature with the shared secret. The token is decoded in your browser and never sent anywhere.

How to Use

1

Paste the token

Paste the JWT into Token. A "Bearer " prefix, quotes and line breaks are removed for you. Click Example to see a sample.

2

Read the header and claims

The coloured view shows the three parts. Header and Payload show the JSON, and Claims explains each field with its time and how long ago or from now it is.

3

Check the signature (optional)

For an HS256, HS384 or HS512 token, enter the secret under Signature. Turn on "Secret is Base64-encoded" if your server stores it that way.

Privacy & Processing

  • Mode: local
  • Files Leave Browser: Local tool processing; review details below
  • Max Input Size: Device memory limits
  • Account Required: No
  • Data Stored Locally: Nothing is saved; the token and secret are gone when you close the page.
  • Network Processing: Assets or models may require an initial download

Tokens and secrets are decoded and checked in your browser. Nothing is uploaded.

Rules & Limitations

  • Decoding is not verification: anyone can read and edit a JWT, so trust it only after a signature check.
  • Signatures can be checked only for HS256, HS384 and HS512 (shared secret). RS256, ES256 and other public-key algorithms are decoded but not checked.
  • Encrypted tokens (JWE, with 5 parts) can't be decoded without the private key; only their header is shown.
  • exp, nbf, iat and auth_time are read as Unix seconds; a 13-digit value is flagged as probably milliseconds.

Top Suggestions

  • Finding out why an API returns 401 (expired token, wrong audience or issuer)
  • Checking which user, roles and scopes a token carries
  • Testing that your server signs HS256 tokens with the right secret
  • Learning how JWTs are built: header, payload and signature

JWT Decoder FAQ

How do I decode a JWT?

Paste the token into the Token box. The header and payload appear as formatted JSON, and the Claims table lists each claim with a short explanation. You can paste it with or without the "Bearer " prefix.

How do I check if a JWT is expired?

Look at the status next to alg and typ: it says, for example, "Expired 3 hours ago" or "Not expired: expires in 2 days". The exp row in Claims shows the exact expiry in IST and in your own time zone.

Does decoding a JWT verify it?

No. The header and payload are only Base64url-encoded, so anyone can read or change them. A token is genuine only if its signature checks out with the right key. Here you can check HS256, HS384 and HS512 tokens with their secret.

How do I verify an HS256 signature?

Paste the token, then type the shared secret in the Signature section. The tool recomputes the HMAC and says "Signature verified" or "Invalid signature". If your secret is stored as Base64, turn on "Secret is Base64-encoded".

Is it safe to paste my token here?

The token and secret are processed in your browser and are not uploaded or saved. Still, a valid token works like a password until it expires, so avoid pasting live production tokens on shared or public computers.

What is the difference between JWS and JWE?

Most JWTs are JWS: signed, three parts, readable by anyone. A JWE is encrypted, has five parts, and only the intended recipient can read its payload. This tool decodes JWS tokens and explains when it sees a JWE.