How to Decode a JWT (and What It Does Not Tell You)
JWT DecoderRead the header, payload and expiry of a JWT. Free, no sign-up.A JSON Web Token (JWT) is three Base64URL-encoded parts separated by dots: header.payload.signature. The header and payload are readable by anyone who has the token; only the signature protects it from being changed.
Decode a token
- Open the JWT Decoder.
- Paste the token, with or without the
Bearerprefix. - Read the pretty-printed header and payload, and the timing claims shown as dates.
The token is decoded in your browser and never sent anywhere. Still, treat tokens like passwords: anyone who copies a valid token can use it until it expires.
The claims you will check most
| Claim | Meaning |
|---|---|
exp |
Expires at (seconds since 1970). After this, the token must be rejected. |
iat |
Issued at. |
nbf |
Not valid before this time. |
sub |
Subject, usually the user id. |
aud, iss |
Who the token is for, and who issued it. |
The decoder shows whether the token is currently valid or expired. To convert other Unix timestamps, use the Timestamp Converter.
Decoding is not verifying
Decoding only reads the contents. It does not prove the token is genuine. Verification needs the issuer’s secret or public key, and secrets should never be pasted into a website. Verify tokens in your server code with a maintained JWT library.
Debugging “401 Unauthorized”
- Check
exp: expired tokens are the most common cause. - Check
audandissmatch what the API expects. - Compare clocks: a server clock that is a few minutes off can make
nbforexpfail.
Need to inspect a single part by hand? The Base64 encoder/decoder can decode Base64URL text too.