Decode a JWT in your browser to read its header and payload, see the exp, iat and nbf dates and whether it has expired. The signature is not verified.
What is JWT Decoder?
JWT Decoder is a free online tool that decodes a JSON Web Token in your browser and shows its header and payload as formatted JSON, with the exp, iat and nbf times as dates and a warning when the token has expired or is not valid yet. It does not verify the signature.
The token is decoded on your device and never sent anywhere. Even so, prefer a token from a test environment: the Terms of Use ask you not to paste secrets such as access tokens.
What it supports
- A signed JWT in its compact form: three Base64URL parts separated by dots, as RFC 7519 describes. Spaces and line breaks around the token are ignored, and so is a Bearer word in front of it in any capitalization, as in an Authorization header.
- The header and the payload are decoded from Base64URL and UTF-8 and written as one JSON object, {"header": …, "payload": …}, with the indentation you choose. Every value, including large numbers, is copied as it is written in the token.
- The signature is checked only for its alphabet (letters, digits, - and _), it is not shown, and it can be empty.
- The exp, iat and nbf claims are shown as ISO 8601 dates in UTC, such as 2023-11-14T23:13:20Z, when they are numbers of seconds since 1 January 1970.
- Warnings: the token has expired when exp is now or earlier, and it is not valid yet when nbf is in the future. Both compare with the clock of your device. A claim that is not a valid time gets a warning too, and so does one that looks like milliseconds, a number above 100,000,000,000: it is not turned into a date, because a date in the year 5138 or later is almost certainly a mistake.
- Other claims, such as sub, iss, aud or roles, are shown as they are. The tool does not interpret them.
Good to know
- The signature is not verified. Decoding shows what the token says, not that it is genuine: anyone can write a token with any claims. Only the program that holds the key can verify it.
- A token is not encrypted. Its header and payload are only encoded, so anyone who has the token can read them. Do not put secrets in a payload.
- Prefer a token from a test environment. The token stays in your browser, but a live access token is a secret, and the Terms of Use ask you not to paste secrets.
- Only the compact, three-part form is read. An encrypted token (JWE, with five parts) is refused, and so is a payload that is not a JSON object.
- The dates and the warnings depend on the clock of your device. If that clock is wrong, they will be wrong too.
- A token that is cut off, or a part that is not valid Base64URL or JSON, is refused with a message that names the part (header, payload or signature) and gives its position. Nothing is repaired.
How do I use JWT Decoder?
- Paste your JWT in the input box. It has three parts separated by dots, as in header.payload.signature. A leading Bearer, as in a copied Authorization header, is ignored. Nothing runs while you type.
- Choose the indentation (“2 spaces” or “4 spaces”) and press “Decode”.
- Read the header and the payload next to your input. The exp, iat and nbf claims are also listed as dates in UTC, and a warning appears if the token has expired or is not valid yet. If the token cannot be decoded, the message names the part that is wrong and gives its position.
- Press “Copy” to put the JSON on your clipboard, or “Download” to save it as converted.json.
Examples
A token that has expired
Paste this token and press “Decode”. The result is the header and the payload as JSON, and the signature is not shown. The exp and iat claims, which are numbers of seconds since 1 January 1970, are also listed as dates in UTC. Because exp is in the past, a warning says the token has expired. The token is only decoded, so the warning does not say whether it is genuine.
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkFkYSIsImlhdCI6MTcwMDAwMDAwMCwiZXhwIjoxNzAwMDAzNjAwfQ.c2lnbmF0dXJl{
"header": {
"alg": "HS256",
"typ": "JWT"
},
"payload": {
"sub": "1234567890",
"name": "Ada",
"iat": 1700000000,
"exp": 1700003600
}
}Expires at 2023-11-14T23:13:20Z
Issued at 2023-11-14T22:13:20Z
This token has expired: its exp claim is in the past. The token is only decoded here and its signature is not verified, so this does not say whether it is genuine.
A token with a missing part
A JWT has exactly three parts. This text has two, so the tool refuses. A token with an empty signature, such as an unsecured token, still needs both dots. An encrypted token (JWE, with five parts) cannot be decoded.
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkFkYSIsImlhdCI6MTcwMDAwMDAwMCwiZXhwIjoxNzAwMDAzNjAwfQA JWT has exactly three parts separated by dots: header.payload.signature. This text does not. Encrypted tokens (JWE, which have five parts) cannot be decoded here.
Line 1, column 1
A pasted Authorization header
The word Bearer and the space are not part of the token, so the tool ignores them and decodes the token as usual. Press “Decode” on the whole header line.
Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiI3IiwiaWF0IjoxNjAwMDAwMDAwfQ.c2lnbmF0dXJl{
"header": {
"alg": "HS256",
"typ": "JWT"
},
"payload": {
"sub": "7",
"iat": 1600000000
}
}Issued at 2020-09-13T12:26:40Z
A token that is not valid yet
The nbf claim (not before) is far in the future, so a warning says the token is not valid yet, and nbf and exp are listed as dates. The tool compares them with the clock of your device at the moment you press “Decode”.
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiI0MiIsIm5iZiI6OTk5OTk5OTk5OSwiZXhwIjoxMDAwMDAwMzU5OX0.c2lnbmF0dXJl{
"header": {
"alg": "HS256",
"typ": "JWT"
},
"payload": {
"sub": "42",
"nbf": 9999999999,
"exp": 10000003599
}
}Expires at 2286-11-20T18:46:39Z
Not valid before 2286-11-20T17:46:39Z
This token is not valid yet: its nbf claim is in the future.
Limits and privacy
Size limits
- Input: up to 2,000,000 bytes of UTF-8 text (about 2 MB). Accented letters and emoji take more than one byte each. Larger input is rejected.
- Result: also up to 2,000,000 bytes. If the complete result would be larger, the tool shows only an incomplete preview of the first 100,000 bytes, and that preview cannot be copied or downloaded.
- Nesting: up to 256 levels of objects and lists (in the header or the payload) inside each other. Deeper JWT is refused because it is beyond what the tool processes.
- Time: a run that takes longer than its time limit is stopped. Try a smaller input.
Is my text sent to a server?
No. The text you type or paste, or open from a local file, is processed locally in your browser, in a dedicated Web Worker. It is never uploaded or sent to the server (a file you open is read in your browser only), and it is not written to storage, cookies or the address bar.
“Copy” puts the result on your clipboard and “Download” saves it as a file, but only when you press the button. The file is created in your browser, so nothing is uploaded.
For the full details, see the Privacy Policy
Related tools and pages
Your text stays in the page when you switch tools in the same tab, so you can try the same text in another tool. Reloading or closing the tab ends it.