Skip to content
EverythingTool logo
Developer

JWT Decoder

Decode JSON Web Tokens to inspect header, payload and expiry. Nothing leaves your browser.

Header

{
  "alg": "HS256",
  "typ": "JWT"
}

Payload

{
  "sub": "1234567890",
  "name": "Aarti Sharma",
  "role": "admin",
  "iat": 1758520000,
  "exp": 2000000000
}
Expires (exp)
Wed, 18 May 2033 03:33:20 GMT
Issued at (iat)
Mon, 22 Sep 2025 05:46:40 GMT

Signature (HS256) is shown undecoded and not verified.

Share this tool WhatsApp X Facebook

How to decode a JWT

Paste a JSON Web Token into the box — with or without the Bearer prefix copied from an Authorization header. The decoder splits it into its three parts, decodes the header and payload, and converts time claims like exp and iat into readable dates so you can see at a glance whether the token has expired.

Anatomy of a JWT

A JWT is three Base64URL-encoded segments joined by dots:

header.payload.signature
  • Header — metadata, usually the signing algorithm (alg, e.g. HS256 or RS256) and token type (typ).
  • Payload — the claims: who the token is about (sub), who issued it (iss), who it's for (aud), when it expires (exp), plus any custom data such as roles or tenant IDs.
  • Signature — a cryptographic signature over the header and payload. It proves the token wasn't tampered with, but only a party holding the key can check it.

Registered claims reference

ClaimNameMeaning
issIssuerWho created and signed the token
subSubjectThe user or entity the token represents
audAudienceWhich service the token is intended for
expExpirationUnix time after which the token is invalid
nbfNot beforeUnix time before which the token is invalid
iatIssued atUnix time the token was created
jtiJWT IDUnique identifier, used to prevent replay

Decoding is not verifying

Anyone can decode a JWT — the payload is just encoded, not encrypted. Your backend must always verify the signature and check exp, iss and aud before trusting a token. Common security mistakes include accepting alg: none, using weak HMAC secrets, and confusing RS256 public keys with HS256 secrets.

Debugging tips

  • 401 errors right after login? Check that exp isn't in the past due to server clock drift.
  • Token rejected by one service only? Compare the aud claim with what that service expects.
  • Missing permissions? Inspect the roles or scope claims in the payload.

Convert raw timestamps with the Unix timestamp converter, or decode individual segments with the Base64 decoder.

Frequently asked questions

Is it safe to paste my JWT here?

Decoding happens entirely in your browser — the token is never sent anywhere. Still, treat production tokens like passwords: anyone holding a valid token can use it until it expires.

Does this tool verify the JWT signature?

No. It decodes the header and payload, which are only Base64URL-encoded and readable by anyone. Verifying the signature requires the secret or public key and should be done on your server with a trusted library.

What do exp, iat and nbf mean?

They are registered claims holding Unix timestamps in seconds: exp is when the token expires, iat is when it was issued, and nbf is the time before which it must not be accepted.

Can I store sensitive data in a JWT payload?

Not in a standard signed JWT (JWS). The payload is readable by anyone who has the token. Use JWE (encrypted JWT) or keep sensitive data server-side.

Last updated: 22 September 2026Suggest an improvement · Report a problem

Official websites, opening in a new tab. EverythingTool isn't affiliated with them.