JWT Decode

Decode a JWT (JSON Web Token): view the header and payload as readable JSON, and see standard fields like exp/iat as dates.

Runs 100% in your browser — your token is never sent to a server.

            

            
This tool only decodes the token's contents, it does not verify the signature. To confirm a JWT was really issued by a trusted server, you must verify the signature with a secret or public key — this can't be safely done in the browser since it requires the secret key.

Try This Next

Finished here? These might be your next step.

Frequently Asked Questions

Yes, this is by design. A JWT's header and payload are only Base64URL-encoded, not encrypted — anyone can decode them. What actually secures a JWT is the signature; the server verifies it with its own secret key to make sure the token hasn't been tampered with. That's why you should never put secrets like passwords inside a JWT.

iat (issued at) is when the token was created, and exp (expiration) is when it stops being valid — both are Unix epoch timestamps in seconds. This tool converts them to a readable date and shows whether the token has expired as a badge above.

Last updated: