The fastest online JWT decoder — paste any JSON Web Token and instantly
decode JWT header, payload and claims. Check expiration, issuer and all standard claims.
Our client-side JWT decoder runs entirely in your browser.
No uploads, no account, 100% private.
JWT Decoder · Claims Inspector · Expiry Check · Signature Verify · Free
Paste your JWT — from an API response, Authorization header or OAuth flow — into the input above.
Click Decode JWT. Header and payload are Base64URL-decoded in your browser. No server contact.
View all claims — sub, iss, exp, iat and custom claims — with human-readable timestamps.
Optionally verify using your HMAC secret or RSA public key — the panel matches the hash to the token's own algorithm automatically.
A JWT decoder is a tool that reads a JSON Web Token and splits it into its three components — header, payload and signature — then decodes the Base64URL-encoded header and payload into readable JSON. This lets you inspect the algorithm, token type, issuer, subject, audience, expiration time and any custom claims without needing the secret key.
This online JWT decoder also acts as a JWT claims inspector and expiry checker — it calculates whether the token is still valid, how much time remains before it expires, or how long ago it expired. It flags a token that uses the insecure alg: none, and optionally verifies the signature entirely in your browser using the Web Crypto API.
| Claim | Full Name | Description |
|---|---|---|
| sub | Subject | The user or entity the token refers to (e.g. user ID) |
| iss | Issuer | The server or service that issued the token |
| aud | Audience | The intended recipient(s) of the token |
| exp | Expiration | Unix timestamp after which the token is invalid |
| iat | Issued At | Unix timestamp when the token was issued |
| nbf | Not Before | Unix timestamp before which the token must not be used |
| jti | JWT ID | Unique identifier for the token (for revocation) |
This JWT decode tool supports all standard JWT formats. Here's how to use each feature:
Paste your JWT (the three-part dot-separated string) into the input field and click Decode JWT. The token is split and decoded instantly. The colour-coded preview under the input shows the header in red, payload in purple and signature in green.
The status banner at the top of the results shows whether the token is Valid, Expired, or has no expiry claim. For each timestamp claim (exp, iat, nbf), the decoder shows both the raw Unix timestamp and a human-readable date with the time remaining or elapsed.
The Verify Signature panel automatically selects the correct tab and hash based on the token's own alg claim once you decode it. For the HMAC family (HS256, HS384, HS512), paste your secret key. For the RSA family (RS256, RS384, RS512), paste the public key in PEM format — only the public key is needed, the private key never needs to leave your server. If the token uses an algorithm outside these two families, the panel tells you so rather than silently attempting the wrong check.
This tool works as a bearer token decoder for OAuth 2.0 access tokens and OpenID Connect ID tokens. If your API returns a Bearer token in the Authorization header, paste just the token string (without the Bearer prefix) to inspect the user claims, scopes, and expiration time.
This JWT decoder for developers is used across authentication, API development and security workflows:
localStorage or cookies to read user identity, roles and expiration without making an extra API call.alg: none tokens, and helps spot overly permissive claims or excessively long expiry times.kubectl get secret) and cloud provider tokens (AWS STS, GCP service accounts) to verify scope and expiry.eyJ) into the input above and click Decode JWT. The header, payload and signature are decoded and displayed instantly with human-readable timestamps for exp, iat and nbf. All decoding happens locally — the token never leaves your browser.alg: none means the token has no cryptographic signature at all — anyone can create or modify a token like this and it will look structurally valid. A server that accepts alg:none tokens can be trivially bypassed; this is a well-documented JWT vulnerability class. This decoder shows a clear warning whenever it detects one.exp (expiration) claim is a Unix timestamp (seconds since January 1, 1970 UTC). The JWT must not be accepted after this time. This decoder converts it to a human-readable date and shows whether the token is still valid, when it expires, or how long ago it expired.