LocalDevTools

JWT Decoder

Paste a JSON Web Token to see its header, payload and expiry in plain language. Decoding happens on your device, which matters because a JWT is often a live credential.

Header
Payload
Verify HMAC signature (HS256 / HS384 / HS512)

Runs entirely in your browser. Your input is never uploaded or stored on a server.

How to decode a JWT

  1. Copy the token, usually from an Authorization: Bearer … header, a cookie or your browser's local storage.
  2. Paste it into the box. The header and payload are decoded instantly as you type.
  3. Check the claims table. exp, iat and nbf are shown as dates in your time zone, with a clear note if the token has expired or is not yet valid.
  4. Optionally open Verify HMAC signature and enter the shared secret to confirm the token was signed with it.

What is inside a JWT?

A JWT is three Base64URL-encoded parts separated by dots: header.payload.signature.

  • Header: the signing algorithm (alg, such as HS256 or RS256) and token type, and sometimes a key ID (kid).
  • Payload: the claims. Registered claims include sub (subject, usually a user ID), iss (issuer), aud (audience), exp (expiry), iat (issued at) and nbf (not before). Times are Unix timestamps in seconds.
  • Signature: proves the header and payload were not changed. It is computed over the first two parts with a secret (HMAC) or a private key (RSA/ECDSA).

Example

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9
.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkFkYSIsImlhdCI6MTcwMDAwMDAwMH0
.<signature>

The first part decodes to {"alg":"HS256","typ":"JWT"} and the second to {"sub":"1234567890","name":"Ada","iat":1700000000}. The iat value is 14 November 2023, 22:13:20 UTC.

Security notes

Decoding is not verifying. Anyone can read a JWT payload, because Base64URL is an encoding, not encryption. Never put passwords or other secrets in a payload, and never trust a token's claims on a server until its signature has been verified with the expected algorithm and key. A classic bug is accepting "alg": "none" or letting the token choose its own algorithm.

Treat production tokens like passwords. Pasting them into a tool that sends data to a server can leak a working session. This page does not make any network request with your token.

Frequently asked questions

Is it safe to paste a production JWT here?

The token is decoded with JavaScript in your browser and is not sent anywhere. Even so, a valid token is a credential, so prefer expired or test tokens when you can, and rotate any token you have shared with a third party.

Why can I read the payload without the secret?

JWTs signed with JWS are encoded, not encrypted. The signature only proves integrity. If you need confidentiality, the issuer must use an encrypted JWE token instead.

Can this tool verify RS256 or ES256 tokens?

Not yet. Verifying asymmetric signatures requires the issuer's public key (often from a JWKS endpoint). This version verifies HMAC algorithms (HS256, HS384, HS512) with a shared secret.

What time zone are exp and iat in?

JWT times are Unix timestamps, which are always UTC-based seconds since 1 January 1970. The table shows them in both UTC and your local time zone.

Why does my token show "Invalid token format"?

Make sure you copied all three parts, including both dots, and did not include the word Bearer or surrounding quotes. The tool strips a leading Bearer automatically.

Related tools

Last updated: