JWT decoder
Show the header and payload of a JSON Web Token. The signature is not checked.
Decoded is not verified. Do not paste production tokens you cannot revoke. Expiration is compared to this device’s clock.
Paste a token to read the header and the payload. The signature is not checked, so decoded does not mean trusted. Do not paste a live token you cannot revoke. The expiration time is compared with this device's clock.
- 1Paste a token.
- 2Read the header and payload.
- 3Check the expired flag if exp is present.
Rate this tool
Questions
- Does it support base64url?
- Yes, including minus, underscore, and missing padding.
- Can it tell me the token is authentic?
- No. Checking the signature would require a secret that should not be typed into a page.
- Nothing is uploaded. Closing the tab drops the file.
- Decoding stays in the tab.