1. Home
  2. Guides
  3. Developer

How to Decode a JWT (and What It Does Not Tell You)

4 min readUpdated October 6, 2026

JWT DecoderRead the header, payload and expiry of a JWT. Free, no sign-up.

A JSON Web Token (JWT) is three Base64URL-encoded parts separated by dots: header.payload.signature. The header and payload are readable by anyone who has the token; only the signature protects it from being changed.

Decode a token

  1. Open the JWT Decoder.
  2. Paste the token, with or without the Bearer prefix.
  3. Read the pretty-printed header and payload, and the timing claims shown as dates.

The token is decoded in your browser and never sent anywhere. Still, treat tokens like passwords: anyone who copies a valid token can use it until it expires.

The claims you will check most

Claim Meaning
exp Expires at (seconds since 1970). After this, the token must be rejected.
iat Issued at.
nbf Not valid before this time.
sub Subject, usually the user id.
aud, iss Who the token is for, and who issued it.

The decoder shows whether the token is currently valid or expired. To convert other Unix timestamps, use the Timestamp Converter.

Decoding is not verifying

Decoding only reads the contents. It does not prove the token is genuine. Verification needs the issuer’s secret or public key, and secrets should never be pasted into a website. Verify tokens in your server code with a maintained JWT library.

Debugging “401 Unauthorized”

  1. Check exp: expired tokens are the most common cause.
  2. Check aud and iss match what the API expects.
  3. Compare clocks: a server clock that is a few minutes off can make nbf or exp fail.

Need to inspect a single part by hand? The Base64 encoder/decoder can decode Base64URL text too.