Free Developer Tool

JWT Decoder

Paste any JSON Web Token to instantly decode the header and payload, check expiry, inspect standard claims, and understand what your token actually contains — all in your browser, nothing sent to any server.

  • ✔ Header & payload decode
  • ✔ Expiry countdown
  • ✔ Standard claim inspector
  • ✔ Algorithm display
  • ✔ Nothing uploaded
  • ✔ Free Forever
eyJhbGciOiJIUzI1NiJ9 . eyJzdWIiOiJ1c2VyX . SflKxwR Header { "alg": "HS256" "typ": "JWT" } Payload { "sub": "user_42" "exp": 1789455322 "iat": 1789451722 } Signature HMACSHA256( base64(hdr) + "." + base64(pld), secret )

Debug JWTs Instantly — No Server Required


JSON Web Tokens appear everywhere in modern APIs — OAuth 2.0 access tokens, OpenID Connect ID tokens, session tokens, and API keys all commonly use the JWT format. When something goes wrong (a 401, an "invalid token" error, or an unexpected claim value), the first step is always the same: decode the token and see what's actually in it.
This tool decodes the Base64URL-encoded header and payload, formats them as readable JSON, highlights standard registered claims (sub, iss, aud, exp, iat, nbf, jti), and shows a live expiry countdown so you can see at a glance whether the token is still valid.

How It Works

1. Paste Your Token

Paste any JWT — the tool accepts the full three-part token or just header.payload.

2. Decode

Header and payload are Base64URL-decoded and formatted as JSON.

3. Inspect Claims

Standard claims (exp, iat, sub, iss) are highlighted with human-readable times.

4. Debug

See whether the token is expired, not yet valid, or missing expected claims.

JWT Standard

Registered Claim Reference

These are the standard registered claims defined in RFC 7519. Custom claims (anything not in this list) are application-specific.

ClaimNameDescription
iss Issuer Identifies the principal that issued the JWT. Usually a URL (e.g. https://auth.example.com).
sub Subject Identifies the principal that is the subject of the JWT — typically a user ID or account identifier.
aud Audience Identifies the recipients the JWT is intended for. The receiving party must reject the JWT if it is not in this list.
exp Expiration Time Unix timestamp after which the token must not be accepted. Always check this before trusting a token.
nbf Not Before Unix timestamp before which the token must not be accepted. Used to delay token validity.
iat Issued At Unix timestamp when the token was issued. Used to determine the token's age.
jti JWT ID A unique identifier for the token. Used to prevent replay attacks by tracking used token IDs.
typ Type Declares the media type of the JWT. Usually omitted or set to JWT.
alg Algorithm Identifies the cryptographic algorithm used to secure the JWT — set in the header, not the payload. Common values: HS256, RS256, ES256.

Common Algorithms

  • HS256 — HMAC + SHA-256. Symmetric (shared secret). Simple but secret must be shared.
  • RS256 — RSA + SHA-256. Asymmetric (public/private key). Standard for production APIs.
  • ES256 — ECDSA + SHA-256. Asymmetric, smaller keys than RSA.
  • none — Unsecured JWT. Never accept in production.

Token Lifetime

  • Access tokens: typically 5–60 minutes.
  • ID tokens (OIDC): typically 1 hour.
  • Refresh tokens: days to months (stored securely, not in JWT).
  • Short-lived tokens reduce the window for abuse if a token is leaked.

Security Notes

  • This tool decodes but cannot verify the signature — that requires the server's secret or public key.
  • Never put sensitive data (passwords, card numbers) in JWT payloads — they are Base64 encoded, not encrypted.
  • Always validate exp, iss, and aud server-side.

FAQsJWT Decoder

Can this tool verify a JWT signature?

No — and intentionally so. Signature verification requires the server's signing secret or public key, which should never be sent to a third-party tool. This tool decodes the header and payload only. Always verify signatures server-side.

Is a JWT encrypted?

No. A standard JWT is Base64URL-encoded, not encrypted. Anyone who has the token can decode and read the payload. Never store sensitive data in a JWT payload.

What is the exp claim?

exp (Expiration Time) is a Unix timestamp after which the token must not be accepted. Always validate exp server-side before acting on any token.

Is my token sent anywhere?

No. Decoding happens entirely in your browser. Nothing is sent to our servers. As a general precaution, use test tokens rather than live production tokens when debugging.

24/7 Support Available:

Our support team is here to assist you around the clock. Get Expert Help, Anytime.