JWT decoder
Decode a JSON Web Token to read its header, payload and expiry. The token never leaves your browser.
In your browser
Decoded in your browser. Tokens often grant access, so never paste production tokens into sites that send them to a server.
Header
Payload
Dates
Check the signature
About this tool
Inspect a JSON Web Token safely. See its header and payload as formatted JSON, check when it was issued and when it expires, and verify HMAC signatures with your secret. Decoding happens on your device.
How to use it
- 1 Paste the token.
- 2 Read the header, payload and dates.
- 3 Optionally enter the secret to verify the signature.
Questions
Is it safe to paste a JWT here?
Yes. The token is decoded in your browser and never sent to our server.
Is my data uploaded?
No. This tool runs in your browser, so your text and files never reach our server.
Is this tool free?
Yes. It’s free to use with no sign-up and no limits for normal use.
More in Encoding & hashing
- HMAC generator New Sign a message with a secret key using HMAC-SHA-1, SHA-256, SHA-384 or SHA-512.
- Base64 decoder Decode Base64 back to text.
- Base64 encoder Encode text to Base64.
- Bcrypt generator Hash a password with bcrypt, or check a password against an existing bcrypt hash.
- Text to number codes Turn text into byte or code-point values and back.
- HTML entity converter Encode special characters as HTML entities, or decode them back.