Skip to main content

JWT Decoder

Read a JWT's header and payload in your browser.

JWT input

Ln 1, Col 1
JWT

Result

Your result will appear here

Add JWT above, then choose Decode.

Add JWT on the left, then choose Decode.

Waiting for input

2 spaces

Decode a JWT in your browser to read its header and payload, see the exp, iat and nbf dates and whether it has expired. The signature is not verified.

What is JWT Decoder?

JWT Decoder is a free online tool that decodes a JSON Web Token in your browser and shows its header and payload as formatted JSON, with the exp, iat and nbf times as dates and a warning when the token has expired or is not valid yet. It does not verify the signature.

The token is decoded on your device and never sent anywhere. Even so, prefer a token from a test environment: the Terms of Use ask you not to paste secrets such as access tokens.

What it supports

  • A signed JWT in its compact form: three Base64URL parts separated by dots, as RFC 7519 describes. Spaces and line breaks around the token are ignored, and so is a Bearer word in front of it in any capitalization, as in an Authorization header.
  • The header and the payload are decoded from Base64URL and UTF-8 and written as one JSON object, {"header": …, "payload": …}, with the indentation you choose. Every value, including large numbers, is copied as it is written in the token.
  • The signature is checked only for its alphabet (letters, digits, - and _), it is not shown, and it can be empty.
  • The exp, iat and nbf claims are shown as ISO 8601 dates in UTC, such as 2023-11-14T23:13:20Z, when they are numbers of seconds since 1 January 1970.
  • Warnings: the token has expired when exp is now or earlier, and it is not valid yet when nbf is in the future. Both compare with the clock of your device. A claim that is not a valid time gets a warning too, and so does one that looks like milliseconds, a number above 100,000,000,000: it is not turned into a date, because a date in the year 5138 or later is almost certainly a mistake.
  • Other claims, such as sub, iss, aud or roles, are shown as they are. The tool does not interpret them.

Good to know

  • The signature is not verified. Decoding shows what the token says, not that it is genuine: anyone can write a token with any claims. Only the program that holds the key can verify it.
  • A token is not encrypted. Its header and payload are only encoded, so anyone who has the token can read them. Do not put secrets in a payload.
  • Prefer a token from a test environment. The token stays in your browser, but a live access token is a secret, and the Terms of Use ask you not to paste secrets.
  • Only the compact, three-part form is read. An encrypted token (JWE, with five parts) is refused, and so is a payload that is not a JSON object.
  • The dates and the warnings depend on the clock of your device. If that clock is wrong, they will be wrong too.
  • A token that is cut off, or a part that is not valid Base64URL or JSON, is refused with a message that names the part (header, payload or signature) and gives its position. Nothing is repaired.

How do I use JWT Decoder?

  1. Paste your JWT in the input box. It has three parts separated by dots, as in header.payload.signature. A leading Bearer, as in a copied Authorization header, is ignored. Nothing runs while you type.
  2. Choose the indentation (“2 spaces” or “4 spaces”) and press “Decode”.
  3. Read the header and the payload next to your input. The exp, iat and nbf claims are also listed as dates in UTC, and a warning appears if the token has expired or is not valid yet. If the token cannot be decoded, the message names the part that is wrong and gives its position.
  4. Press “Copy” to put the JSON on your clipboard, or “Download” to save it as converted.json.

Examples

A token that has expired

Paste this token and press “Decode”. The result is the header and the payload as JSON, and the signature is not shown. The exp and iat claims, which are numbers of seconds since 1 January 1970, are also listed as dates in UTC. Because exp is in the past, a warning says the token has expired. The token is only decoded, so the warning does not say whether it is genuine.

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkFkYSIsImlhdCI6MTcwMDAwMDAwMCwiZXhwIjoxNzAwMDAzNjAwfQ.c2lnbmF0dXJl
{
  "header": {
    "alg": "HS256",
    "typ": "JWT"
  },
  "payload": {
    "sub": "1234567890",
    "name": "Ada",
    "iat": 1700000000,
    "exp": 1700003600
  }
}

Expires at 2023-11-14T23:13:20Z

Issued at 2023-11-14T22:13:20Z

This token has expired: its exp claim is in the past. The token is only decoded here and its signature is not verified, so this does not say whether it is genuine.

A token with a missing part

A JWT has exactly three parts. This text has two, so the tool refuses. A token with an empty signature, such as an unsecured token, still needs both dots. An encrypted token (JWE, with five parts) cannot be decoded.

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkFkYSIsImlhdCI6MTcwMDAwMDAwMCwiZXhwIjoxNzAwMDAzNjAwfQ

A JWT has exactly three parts separated by dots: header.payload.signature. This text does not. Encrypted tokens (JWE, which have five parts) cannot be decoded here.

Line 1, column 1

A pasted Authorization header

The word Bearer and the space are not part of the token, so the tool ignores them and decodes the token as usual. Press “Decode” on the whole header line.

Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiI3IiwiaWF0IjoxNjAwMDAwMDAwfQ.c2lnbmF0dXJl
{
  "header": {
    "alg": "HS256",
    "typ": "JWT"
  },
  "payload": {
    "sub": "7",
    "iat": 1600000000
  }
}

Issued at 2020-09-13T12:26:40Z

A token that is not valid yet

The nbf claim (not before) is far in the future, so a warning says the token is not valid yet, and nbf and exp are listed as dates. The tool compares them with the clock of your device at the moment you press “Decode”.

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiI0MiIsIm5iZiI6OTk5OTk5OTk5OSwiZXhwIjoxMDAwMDAwMzU5OX0.c2lnbmF0dXJl
{
  "header": {
    "alg": "HS256",
    "typ": "JWT"
  },
  "payload": {
    "sub": "42",
    "nbf": 9999999999,
    "exp": 10000003599
  }
}

Expires at 2286-11-20T18:46:39Z

Not valid before 2286-11-20T17:46:39Z

This token is not valid yet: its nbf claim is in the future.

Limits and privacy

Size limits

  • Input: up to 2,000,000 bytes of UTF-8 text (about 2 MB). Accented letters and emoji take more than one byte each. Larger input is rejected.
  • Result: also up to 2,000,000 bytes. If the complete result would be larger, the tool shows only an incomplete preview of the first 100,000 bytes, and that preview cannot be copied or downloaded.
  • Nesting: up to 256 levels of objects and lists (in the header or the payload) inside each other. Deeper JWT is refused because it is beyond what the tool processes.
  • Time: a run that takes longer than its time limit is stopped. Try a smaller input.

Is my text sent to a server?

No. The text you type or paste, or open from a local file, is processed locally in your browser, in a dedicated Web Worker. It is never uploaded or sent to the server (a file you open is read in your browser only), and it is not written to storage, cookies or the address bar.

“Copy” puts the result on your clipboard and “Download” saves it as a file, but only when you press the button. The file is created in your browser, so nothing is uploaded.

For the full details, see the Privacy Policy

Related tools and pages

Your text stays in the page when you switch tools in the same tab, so you can try the same text in another tool. Reloading or closing the tab ends it.

All tools

Format, validate and convert JSON, YAML, XML, CSV, HTML, CSS and Markdown, plus Base64, URL and JWT.

JSON

  • JSON Formatter

    Format JSON with one consistent layout: even indentation, one value per line, your values untouched. Runs the same formatter as JSON Beautifier.

  • JSON Validator

    Check whether your text is valid JSON. If it is not, see the first problem with its line and column, highlighted in your text.

  • JSON Diff

    Compare two JSON documents by structure, ignoring key order, and see every added, removed and changed path in one list.

  • JSON Schema Validator

    Validate JSON against a JSON Schema (draft 2020-12, or draft-07 through $schema) and see each error with the path where it occurs.

  • JSON Schema Generator

    Generate a JSON Schema (draft 2020-12) from a sample JSON document, ready to copy and refine.

  • JSON Beautifier

    Beautify minified or unevenly spaced JSON into readable, indented text, with your values untouched. Runs the same formatter as JSON Formatter.

Convert JSON

  • JSON to CSV

    Convert a JSON list of objects, or the first list of objects inside an object, to plain CSV text.

  • CSV to JSON

    Convert CSV to a JSON array of objects, using the header row as keys. Comma, semicolon and tab separators are detected, and values stay as text.

  • JSON to XML

    Convert JSON to plain, readable XML, with your numbers and text copied exactly as written.

  • XML to JSON

    Convert XML to JSON, with attributes as @name keys and repeated elements gathered into arrays so the structure carries over.

  • JSON to YAML

    Convert JSON to readable block YAML with 2 or 4 spaces of indentation, keeping every value and every number exactly as you wrote it.

  • YAML to JSON

    Convert YAML to JSON with anchors and aliases resolved. A file with several documents becomes a JSON array.

YAML

  • YAML Validator

    Check whether your YAML is valid under the YAML 1.2 Core rules, in one or several documents, and see the line and column of the first problem.

  • YAML Viewer

    Explore a YAML document as a tree you can open and close, with anchors, tags and aliases marked on the row where they appear.

  • YAML Formatter

    Format YAML with consistent indentation while keeping comments and values.

HTML, XML and CSS

  • HTML Formatter

    Format HTML into readable, indented markup. The result is plain text: scripts do not run and nothing in your HTML is loaded.

  • XML Formatter

    Format XML with clear indentation while preserving its content and meaning.

  • CSS Beautifier

    Beautify minified CSS into readable rules, one declaration per line, without changing what the CSS does. Runs the same formatter as CSS Formatter.

  • CSS Formatter

    Format CSS you maintain with one consistent style: the same indentation, spacing and spelling everywhere. Runs the same formatter as CSS Beautifier.

Encode & Decode

  • Base64 Encode/Decode

    Encode text to Base64 or decode Base64 back to text as UTF-8, with an option for the URL-safe Base64URL alphabet.

  • URL Encode/Decode

    Encode or decode text with %XX sequences, either as a URL component or as a full URL whose separators stay intact.

  • JWT Decoder

    Decode a JWT in your browser to read its header and payload, see the exp, iat and nbf dates and whether it has expired. The signature is not verified.

Markdown

New
  • Markdown Editor

    Free online Markdown editor and viewer: write or open an MD file, see a live GFM preview, then copy or download your Markdown.

  • Markdown to PDF

    Convert Markdown to PDF in your browser. Pick A4 or Letter paper and the margins, preview the document and download a real PDF file.

  • Markdown to Text

    Convert Markdown to plain text without losing code or punctuation. Choose how links appear, then copy the text or download a TXT file.

  • Markdown to Word

    Convert Markdown to Word: download an editable DOCX file that keeps headings, lists, tables and links. It runs in your browser.

  • Markdown to HTML

    Convert Markdown to HTML in your browser. Get an HTML fragment or a full document, check the preview, then copy or download it.

  • Markdown Table Generator

    Markdown table generator with an editable grid and column alignment. Import CSV or TSV, then copy or download the Markdown table.

  • Word to Markdown

    Convert Word to Markdown: open a DOCX file and get its headings, lists, links and tables as editable Markdown, all in your browser.

  • HTML to Markdown

    Convert HTML to Markdown from pasted markup or a local file. Scripts never run; headings, lists, links and simple tables carry over.

  • Markdown Formatter

    Markdown formatter that tidies your source and lists style suggestions for headings, spaces and the final newline. Review it before you copy.

  • Markdown to Image

    Convert Markdown to an image: choose the width and theme, preview your note or table and download a PNG or JPEG file.

  • Markdown to Rich Text

    Convert Markdown to rich text and copy it, formatted, into a document editor. Plain text is the fallback when rich copy is unavailable.

  • Markdown Table to JSON/CSV

    Convert a Markdown table to JSON or CSV. Review the headers and pick each column's type, so IDs and leading zeros stay as they are.

  • Excel to Markdown

    Convert Excel to Markdown: open an XLSX file, pick a sheet or a cell range and get a Markdown table without uploading the file.

  • Markdown to Excel

    Convert Markdown tables to Excel: download an XLSX file whose cells stay text, so leading zeros survive and nothing becomes a formula.

  • Paste to Markdown

    Paste to Markdown: turn copied rich text or HTML into Markdown. For plain text, apply heading and list actions yourself, then copy.

  • Markdown Compare

    Markdown compare: paste two versions or open two files and see which lines were added or removed in the source text.

  • Markdown to Mind Map

    Convert Markdown to a mind map: headings and lists become a map you can navigate and export. Built with Markmap, no account needed.

  • Mermaid Editor

    Mermaid live editor in your browser: write diagram code, see the preview and any syntax errors, and export SVG or PNG without an account.

  • Discord Markdown Preview

    Discord Markdown preview: check bold, code blocks and spoilers in an approximate local preview, then copy the message. No Discord account.

  • Obsidian Markdown Converter

    Obsidian Markdown converter: adapt [[wiki links]] and embeds to standard Markdown and list the files your note refers to.

  • GitHub README Viewer

    GitHub README viewer: paste or open a README, see a GFM preview and set a base URL for relative links. Nothing is fetched from GitHub.

  • PDF to Markdown

    Convert PDF to Markdown locally: extract its text layer or run OCR on selected pages without text. Review and edit before copying or downloading.

  • Image to Markdown

    Convert an image to Markdown with OCR in your browser: read text from a PNG or JPEG, correct it, then copy or download. Accuracy varies.