JWT Decoder
Decode a JSON Web Token's header and payload, with readable dates for exp, iat
and nbf. Everything runs in your browser — the token is never sent anywhere and nothing
is stored. This tool decodes only; it does not verify the signature.
The signature is shown as-is. Verifying it proves the token is authentic, but that needs the signing secret or public key — do that in your backend, not here.
More PAYATE tools
Frequently asked questions
What is a JWT?
A JSON Web Token (JWT) is a compact, URL-safe token used to carry claims between two parties — most often for authentication and authorization. It has three Base64URL parts separated by dots: header.payload.signature.
Is my token sent anywhere?
No. This decoder runs entirely in your browser with JavaScript — the token is never uploaded to a server and nothing is stored. Even so, treat production tokens as secrets and avoid pasting them on machines you do not trust.
Does this verify the signature?
No. This tool decodes and inspects the header and payload only. Verifying the signature proves the token is authentic and untampered, but it requires the signing secret or public key, which you should never paste into a web page. Verify signatures in your backend instead.
What do exp, iat and nbf mean?
They are standard time claims, expressed as Unix timestamps: iat (issued-at), nbf (not-before, the token is invalid earlier than this), and exp (expiry, the token is invalid after this). This tool converts them to readable dates and flags an expired token.
Is Base64URL the same as Base64?
Almost — Base64URL replaces + and / with - and _ and drops the = padding, so the token is safe inside a URL. The decoder handles the conversion for you.