JWT Decoder

Decode a JWT's header and payload, with expiry times rendered as readable dates. Decoding only — the token never leaves your browser and is never stored.

Runs in your browser: input and output are never sent to the server, and the platform does not store your input.

Input

Not stored

The token stays in your browser's memory: it is never uploaded and never written to history.

Output

Fill in the fields on the left, then run.

How to use

  1. 1Paste the JWT.
  2. 2Read the header, payload and expiry.
  3. 3Everything disappears when you leave the page.

FAQ

Does it verify the signature?

No. Verification needs the secret key, and this tool only decodes — so you never have to paste a key into a website.

Is the token stored?

No. This tool is marked as not persisting input: nothing is written to the database, and the token itself never reaches the platform.

How do I read the expiry?

If the payload contains exp or iat, the output converts them into readable dates and states whether the token has expired.