What it does
A JSON Web Token (JWT) is a compact string with three parts separated by dots: a header that names the signing algorithm, a payload with claims about the user or session, and a signature. JWTs are used for login sessions, OAuth 2.0 access tokens and OpenID Connect ID tokens.
The header and payload are only Base64URL-encoded, not encrypted. This tool decodes them into readable, formatted JSON and explains the standard time claims, so you can see who the token is for, which permissions it carries and whether it has expired.
How to use
- Paste a token into Encoded token. A leading
Bearerfrom an Authorization header is removed automatically. - Read the status badge: Not expired, Expired, Not valid yet or No expiry.
- Check the issued-at, not-before and expiry times, shown in your local time and as Unix seconds.
- Copy the formatted header or payload JSON with the Copy buttons.
Example
The sample token has this header and payload:
{ "alg": "HS256", "typ": "JWT" }
{
"sub": "1234567890",
"name": "张三 Jane Doe",
"roles": ["admin", "editor"],
"iat": 1700000000,
"exp": 4102444800
}
Common claims
ississuer,subsubject (usually the user ID),audaudienceiatissued at,nbfnot before,expexpiration time, all in Unix secondsjtia unique token ID, often used to revoke tokens
FAQ
› Is it safe to paste my token here?
The token is decoded in your browser and never sent anywhere. Even so, treat production tokens like passwords; anyone who has a valid token can use it until it expires.
› Does this tool verify the signature?
No. Verifying needs the secret key (HS256) or the issuer's public key (RS256, ES256). Decoding only reads the contents, which are not encrypted, just Base64URL-encoded. Never trust claims from a token your server has not verified.
› Why does it say "Expired"?
The exp claim is earlier than your device's current time. Check that your clock is correct, then request a new token from the issuer.
› Can it decode encrypted tokens (JWE)?
No. A JWE has five parts and its payload is encrypted, so it cannot be read without the decryption key.