jwt decoder
runs in your browser, nothing is uploaded
IDLE
Paste a JSON Web Token to read its header and payload as formatted JSON, with the times in it shown as dates. Decoding happens in your browser, and the token is not sent anywhere.
What you can paste
A bare token such as eyJhbGciOi…, the same token after Bearer as copied from an Authorization header, or any JSON that holds tokens as string values. A bare token gets a decode jwt button; tokens inside JSON get a jwt badge you can click to expand.
The header and payload are decoded from base64url and shown as a tree. Claims such as exp, iat and nbf show the date they stand for, and selecting the token shows its algorithm and whether it has expired.
What decoding does not do
The signature is not verified. Decoding shows what the token says, but it cannot tell you whether the token is genuine; that takes the signing key and a check on your server. Encrypted tokens (JWE) cannot be read here either.
Tokens are often credentials. Nothing is uploaded, but what you paste is saved in this browser between visits, so on a shared computer use “clear saved data” in the help dialog when you are done.
Questions
Is it safe to paste a token here?
The token stays in this page and is not uploaded. It is saved in this browser until you clear it, so treat a live token with the same care as a password.
Does it check the signature?
No. It only decodes. Anyone can create a token with any payload, so never trust its contents without verifying the signature on your server.
Why is my token reported as invalid JSON?
Extra text around it, such as a header name, stops it being recognised as a bare token. Paste just the token, optionally after Bearer .
Can it decode encrypted tokens?
No. Encrypted tokens (JWE) have five parts and cannot be read without the key. Only tokens with a readable header and payload can be decoded.