Skip to content
Toolbench

JWT decoder

Decode a JSON Web Token to read its header, payload and expiry. The token never leaves your browser.

In your browser

Decoded in your browser. Tokens often grant access, so never paste production tokens into sites that send them to a server.

About this tool

Inspect a JSON Web Token safely. See its header and payload as formatted JSON, check when it was issued and when it expires, and verify HMAC signatures with your secret. Decoding happens on your device.

How to use it

  1. 1 Paste the token.
  2. 2 Read the header, payload and dates.
  3. 3 Optionally enter the secret to verify the signature.

Questions

Is it safe to paste a JWT here?

Yes. The token is decoded in your browser and never sent to our server.

Is my data uploaded?

No. This tool runs in your browser, so your text and files never reach our server.

Is this tool free?

Yes. It’s free to use with no sign-up and no limits for normal use.