No — and intentionally so. Signature verification requires the server's signing secret or public key, which should never be sent to a third-party tool. This tool decodes the header and payload only. Always verify signatures server-side.
Paste any JSON Web Token to instantly decode the header and payload, check expiry, inspect standard claims, and understand what your token actually contains — all in your browser, nothing sent to any server.
Paste any JWT — the tool accepts the full three-part token or just header.payload.
Header and payload are Base64URL-decoded and formatted as JSON.
Standard claims (exp, iat, sub, iss) are highlighted with human-readable times.
See whether the token is expired, not yet valid, or missing expected claims.
These are the standard registered claims defined in RFC 7519. Custom claims (anything not in this list) are application-specific.
| Claim | Name | Description |
|---|---|---|
| iss | Issuer | Identifies the principal that issued the JWT. Usually a URL (e.g. https://auth.example.com). |
| sub | Subject | Identifies the principal that is the subject of the JWT — typically a user ID or account identifier. |
| aud | Audience | Identifies the recipients the JWT is intended for. The receiving party must reject the JWT if it is not in this list. |
| exp | Expiration Time | Unix timestamp after which the token must not be accepted. Always check this before trusting a token. |
| nbf | Not Before | Unix timestamp before which the token must not be accepted. Used to delay token validity. |
| iat | Issued At | Unix timestamp when the token was issued. Used to determine the token's age. |
| jti | JWT ID | A unique identifier for the token. Used to prevent replay attacks by tracking used token IDs. |
| typ | Type | Declares the media type of the JWT. Usually omitted or set to JWT. |
| alg | Algorithm | Identifies the cryptographic algorithm used to secure the JWT — set in the header, not the payload. Common values: HS256, RS256, ES256. |
exp, iss, and aud server-side.No — and intentionally so. Signature verification requires the server's signing secret or public key, which should never be sent to a third-party tool. This tool decodes the header and payload only. Always verify signatures server-side.
No. A standard JWT is Base64URL-encoded, not encrypted. Anyone who has the token can decode and read the payload. Never store sensitive data in a JWT payload.
exp (Expiration Time) is a Unix timestamp after which the token must not be accepted. Always validate exp server-side before acting on any token.
No. Decoding happens entirely in your browser. Nothing is sent to our servers. As a general precaution, use test tokens rather than live production tokens when debugging.