JWT Decoder
Decode a JWT's header and payload with readable timestamps for exp/nbf/iat — decoding only, never signature verification.
Decoding happens entirely in your browser. The token you paste is never sent to a server and is never logged anywhere by this tool.
A JWT (JSON Web Token) has three dot-separated parts — a header, a payload, and a signature. The header and payload are just Base64URL-encoded JSON, so anyone can decode and read them without any key; only the signature can prove the token is genuine, and checking it requires the issuer's secret or public key, which this tool never has.
Standard claims: exp (expiration), nbf (not valid before), and iat (issued at) are Unix timestamps (seconds since 1970) — shown here as readable dates. iss, sub, and aud identify the issuer, subject, and intended audience.
A common mistake is treating a successfully-decoded token as proof it's legitimate. Anyone can construct a syntactically valid JWT with any claims they like — decoding it will always "work." Whether to trust it depends entirely on verifying its signature server-side, which is a separate step this tool deliberately does not perform.