Skip to content

JWT Decoder

Read the header and claims of a JSON Web Token and check when it expires.

FreeRuns in your browserToken never sent
Decoded locally. The token is never sent to a server.

What is a JWT?

A JSON Web Token is a compact, signed string used for logins and API access.

It has three parts separated by dots: the header (algorithm), the payload (claims such as user ID and expiry) and the signature. The first two are only encoded, not encrypted.

Common JWT claims

ClaimMeaning
issIssuer - who created the token
subSubject - usually the user ID
audAudience - which service the token is for
expExpiry time
iatIssued-at time
nbfNot valid before this time
jtiUnique token ID, used to block replay

JWT security checklist

  • Reject alg: none and pin the algorithms your server accepts.
  • Keep access tokens short-lived (minutes, not days).
  • Never put passwords or personal data in the payload.
  • Use long random secrets for HS256 - generate one with the Password Generator.

Working with encoded data? The Base64 Encoder / Decoder handles Base64URL too.

Frequently asked questions

Is it safe to paste a JWT here?

The token is decoded in your browser and never sent anywhere. Still, treat a live token like a password: anyone who has it can use it until it expires. Prefer expired or test tokens.

Does decoding verify the signature?

No. Decoding only reads the header and payload, which are just Base64URL-encoded JSON. Verifying the signature needs the secret or public key and must happen on your server.

Why is "alg: none" dangerous?

A token with alg: none has no signature at all. If a server accepts it, anyone can forge tokens. Servers must reject it and only allow the algorithms they expect.

What do exp, iat and nbf mean?

exp is when the token expires, iat when it was issued and nbf the earliest time it is valid. All are Unix timestamps - this tool converts them to readable dates.

Can I put sensitive data in a JWT?

Not in a normal signed JWT - its payload is readable by anyone, as this tool shows. Store only identifiers and permissions, or use an encrypted JWE.