JWT Decoder
Paste a JSON Web Token to decode its header, payload claims, and expiry — instantly, and 100% in your browser. Your token never leaves this page.
| Claim | Value | Interpreted |
|---|---|---|
| No token decoded yet. | ||
Decoding is not verification: this tool shows what a token contains but cannot prove it is authentic. Never trust claims without server-side signature verification.
How JWT decoding works
A JWT has three parts separated by dots. The header and payload are base64url-encoded JSON — this page decodes them locally and pretty-prints the result. The registered time claims exp (expiry), iat (issued at), and nbf (not before) are converted to readable UTC dates with a live valid/expired/not-yet-valid status.
Why decode client-side?
Some online decoders send your token to their server to format it. A JWT often carries session identifiers and internal user data, so uploading it is an unnecessary risk. This decoder runs entirely on your machine — open the network tab and you'll see zero requests while you paste and inspect tokens.