Skip to content
SPCXTools

JWT Decoder

Decode JSON Web Tokens, check expiry and verify HMAC signatures — privately, in your browser.

Runs locally — files never leave your device

Loading tool…

How to use JWT Decoder

  1. 1Paste a JWT (three Base64URL parts separated by dots) into the Token box, or click Load sample.
  2. 2Read the decoded Header and Payload as formatted JSON.
  3. 3Check the status line to see whether the token is valid, expired or not yet valid; time claims are shown as readable dates.
  4. 4For HS256, HS384 or HS512 tokens, enter the secret to verify the signature locally.

Decode JSON Web Tokens

A JSON Web Token (JWT) is a compact string used to pass identity and permission information between systems — most often as an Authorization: Bearer header after logging in. It looks like random text, but it is three Base64URL-encoded parts: a header, a payload of claims, and a signature. This JWT decoder splits the token, decodes the first two parts into readable JSON and explains the important claims. Decoding and verification happen locally, so your token is never transmitted.

Features

  • Header and payload decoded and pretty-printed, each with a copy button.
  • Time claims explained: iat, nbf, exp and auth_time converted from epoch seconds to dates in your time zone.
  • Expiry check that tells you at a glance whether the token is expired or not yet active.
  • HMAC signature verification for HS256, HS384 and HS512 using your browser's Web Crypto API.
  • Works offline after the page loads; no data is sent anywhere.

When to use it

Debugging authentication. When a request fails with 401 Unauthorized, decode the token to check whether it has expired, was issued for the right audience (aud) or carries the expected roles and scopes.

Building and testing APIs. Verify that your server puts the claims you intended into the token, with correct expiration times, before you ship.

Learning how OAuth and OpenID Connect work. ID tokens and access tokens from identity providers are often JWTs. Decoding a test token shows what information the provider shares about a user.

Anatomy of a JWT

header.payload.signature

  • Header — the token type and signing algorithm, for example {"alg":"HS256","typ":"JWT"}.
  • Payload — the claims. Registered claims include iss (issuer), sub (subject, usually the user ID), aud (audience), exp, nbf, iat and jti (token ID). Apps add custom claims such as name or role.
  • Signature — created by signing header.payload with a secret (HMAC) or a private key (RSA, ECDSA, EdDSA). If anyone changes even one character of the header or payload, the signature no longer matches.

Because the payload is only encoded, never put secrets such as passwords into a JWT. To decode other Base64 data, use the Base64 tool; to inspect any timestamp, use the Unix Timestamp Converter.

Frequently asked questions

Is it safe to paste a real token here?
The token is decoded and verified entirely in your browser and is never sent to our server. Still, a JWT is a credential — treat it like a password, avoid sharing production tokens, and prefer test tokens when possible.
Does decoding a JWT prove it is genuine?
No. Anyone can decode the header and payload because they are only Base64URL-encoded, not encrypted. A token is trustworthy only if its signature is verified with the correct key. For HMAC tokens you can verify here by entering the secret; RSA and ECDSA tokens must be verified with the issuer's public key in your application.
What do exp, iat and nbf mean?
exp (expiration time) is when the token stops being valid, iat (issued at) is when it was created, and nbf (not before) is the earliest time it may be used. All three are Unix timestamps in seconds; the decoder converts them into dates in your time zone.
Why does it say the token is invalid?
A JWT must have exactly three parts separated by dots, and the first two must be Base64URL-encoded JSON. Check that you copied the whole token without the Bearer prefix, quotes or line breaks.
Can it decode encrypted tokens (JWE)?
No. Encrypted JWTs have five parts and their payload can only be read with the decryption key. This tool handles signed tokens (JWS), which is what most APIs use.