All / Developer

JWT decoder

Show the header and payload of a JSON Web Token. The signature is not checked.

Decoded is not verified. Do not paste production tokens you cannot revoke. Expiration is compared to this device’s clock.

Paste a token to read the header and the payload. The signature is not checked, so decoded does not mean trusted. Do not paste a live token you cannot revoke. The expiration time is compared with this device's clock.

  1. 1Paste a token.
  2. 2Read the header and payload.
  3. 3Check the expired flag if exp is present.

Rate this tool

Questions

Does it support base64url?
Yes, including minus, underscore, and missing padding.
Can it tell me the token is authentic?
No. Checking the signature would require a secret that should not be typed into a page.
Nothing is uploaded. Closing the tab drops the file.
Decoding stays in the tab.

Related