Developer
JWT Decoder
Paste a JSON Web Token to read its header and payload. Timestamps are shown as readable dates and expiry is checked against your clock.
Good to know
Frequently asked questions
Does this verify the signature?
No. Verification requires your signing key, which should never be pasted into a website. Verify server-side instead.
Is my token uploaded?
No. Decoding happens entirely in your browser.
Why are exp and iat shown as dates?
They are Unix timestamps in seconds; the tool converts them to your local time for readability.
Is a JWT encrypted?
Not usually. A standard JWT is signed, not encrypted, so anyone holding it can read the payload.