Skip to the tool

JWT decoder

Paste a token, read the header, payload and expiry in plain English. Decoded on your device, never sent to anyone, including us.

Guide

How to use it

  1. Paste the token, straight from a header or debugger. A Bearer prefix is stripped for you.
  2. Read the badge: expired, not yet valid or within validity, from the token's own time claims.
  3. The coloured strip shows the three raw segments; header and payload appear pretty printed beneath.
  4. Recognised claims (alg, iss, sub, aud, scope) are explained in the table.
  5. Just need the expiry countdown? The expiry checker leads with it.

Examples

Worked examples

The mystery 401

An API call fails after lunch. Paste the token: expired 43 minutes ago, at 13:02. The refresh logic is broken, not the API.

The clock-skew token

A token minted by a server with a fast clock shows NOT YET VALID for 30 seconds, exactly the bug that only reproduces on one machine.

The missing scope

A 403 despite a valid login. The payload's scope claim reads read:orders only, the write scope was never requested. Fix the auth request, not the endpoint.

Method

How it works

A JWT is three base64url-encoded segments joined by dots: a JSON header, a JSON payload and a signature over the first two. This page decodes the first two segments and parses the JSON, translating the registered time claims into dates and relative times. The signature is left alone, deliberately: checking it requires the signing key, and a page that asked for your keys would deserve suspicion.

Built by Wolds Cyber. Decoding happens on your device and the page works offline.

FAQ

Frequently asked questions

Is it safe to paste a real token here?

The token is decoded in your browser and never transmitted, which you can verify by going offline. Still, treat live production tokens like passwords: prefer expired ones for debugging, and rotate anything you suspect has leaked.

Why is the signature not verified?

Verifying needs the secret or public key, which this page deliberately does not ask for. Decoding shows what the token claims; only your server, holding the key, can decide whether to believe it.

Why can anyone read my JWT?

JWTs are encoded, not encrypted. Base64url is a transport format, so anyone holding the token reads its contents. Never put secrets in a JWT payload. The explainer covers this properly.

What are iat, exp and nbf?

Unix timestamps: iat is when the token was issued, exp when it expires and nbf the moment before which it must be rejected. This decoder translates all three into dates and relative times.

My token has only two parts. Is that valid?

That is an unsecured JWT (alg none), legal in the spec but rejected by any sensible server. The decoder flags it, since a token without a signature proves nothing.

Why does my API reject a token this page says is within validity?

Validity here means the time claims only. Servers also check the signature, issuer, audience and scopes, and any of those can fail independently of exp.

More tools

Related tools

JWT expiry checkerJust the countdown: is this token expired and when. What is a JWT?The plain-English explainer, with the decoder embedded. Base64 decodeThe encoding JWT segments are built from. SHA-256 generatorThe hash inside HS256 and RS256 signatures.
Skip to the tool

JWT decoder

Paste a token, read the header, payload and expiry in plain English. Decoded on your device, never sent to anyone, including us.

Decode only.

The signature is NOT verified, so treat the contents as claims, not facts. The token never leaves your browser.

Paste a token to read its header and payload.

Everything runs in your browser. Tokens are decoded on your device and never transmitted or logged.

Guide

How to use it

  1. Paste the token, straight from a header or debugger. A Bearer prefix is stripped for you.
  2. Read the badge: expired, not yet valid or within validity, from the token's own time claims.
  3. The coloured strip shows the three raw segments; header and payload appear pretty printed beneath.
  4. Recognised claims (alg, iss, sub, aud, scope) are explained in the table.
  5. Just need the expiry countdown? The expiry checker leads with it.

Examples

Worked examples

The mystery 401

An API call fails after lunch. Paste the token: expired 43 minutes ago, at 13:02. The refresh logic is broken, not the API.

The clock-skew token

A token minted by a server with a fast clock shows NOT YET VALID for 30 seconds, exactly the bug that only reproduces on one machine.

The missing scope

A 403 despite a valid login. The payload's scope claim reads read:orders only, the write scope was never requested. Fix the auth request, not the endpoint.

Method

How it works

A JWT is three base64url-encoded segments joined by dots: a JSON header, a JSON payload and a signature over the first two. This page decodes the first two segments and parses the JSON, translating the registered time claims into dates and relative times. The signature is left alone, deliberately: checking it requires the signing key, and a page that asked for your keys would deserve suspicion.

Built by Wolds Cyber. Decoding happens on your device and the page works offline.

FAQ

Frequently asked questions

Is it safe to paste a real token here?

The token is decoded in your browser and never transmitted, which you can verify by going offline. Still, treat live production tokens like passwords: prefer expired ones for debugging, and rotate anything you suspect has leaked.

Why is the signature not verified?

Verifying needs the secret or public key, which this page deliberately does not ask for. Decoding shows what the token claims; only your server, holding the key, can decide whether to believe it.

Why can anyone read my JWT?

JWTs are encoded, not encrypted. Base64url is a transport format, so anyone holding the token reads its contents. Never put secrets in a JWT payload. The explainer covers this properly.

What are iat, exp and nbf?

Unix timestamps: iat is when the token was issued, exp when it expires and nbf the moment before which it must be rejected. This decoder translates all three into dates and relative times.

My token has only two parts. Is that valid?

That is an unsecured JWT (alg none), legal in the spec but rejected by any sensible server. The decoder flags it, since a token without a signature proves nothing.

Why does my API reject a token this page says is within validity?

Validity here means the time claims only. Servers also check the signature, issuer, audience and scopes, and any of those can fail independently of exp.

More tools

Related tools