JWT Decoder
Decode a JWT's header and payload, with expiry times rendered as readable dates. Decoding only — the token never leaves your browser and is never stored.
Runs in your browser: input and output are never sent to the server, and the platform does not store your input.
Output
Fill in the fields on the left, then run.
How to use
- 1Paste the JWT.
- 2Read the header, payload and expiry.
- 3Everything disappears when you leave the page.
FAQ
Does it verify the signature?
No. Verification needs the secret key, and this tool only decodes — so you never have to paste a key into a website.
Is the token stored?
No. This tool is marked as not persisting input: nothing is written to the database, and the token itself never reaches the platform.
How do I read the expiry?
If the payload contains exp or iat, the output converts them into readable dates and states whether the token has expired.
