Paste a JSON Web Token to inspect its header, payload, expiry and claims — decoded locally, never sent.
Paste the token, read the claims.
Paste the JWT (it starts with eyJ…) into the field.
The header and payload are decoded and pretty-printed instantly.
Check exp, iat and other claims with human-readable dates.
Read the validity status — expired tokens are flagged clearly.
Built for speed, privacy and reliability — on any device.
Both JSON sections are pretty-printed and readable instantly.
exp, iat, nbf, iss and sub claims are shown with human-readable dates.
The tool tells you exactly whether a token is still valid or how long ago it expired.
Decoding runs locally — tokens never reach a server.
No account, no limits.
No — and no browser tool honestly can, because verification needs the secret or public key. Decoding shows the claims; always verify the signature server-side before trusting a token.
No. Decoding runs entirely in your browser — the token never leaves your device.
Standard JWT claims: exp is the expiry time and iat is the issue time, both stored as Unix timestamps and shown here as readable dates.
A JWT must have three dot-separated base64url parts containing valid JSON. Check that you copied the whole token, without extra spaces.
The tool works in all modern browsers including Google Chrome, Mozilla Firefox, Microsoft Edge, Safari and Opera. We recommend keeping your browser up to date for the best experience.
Step-by-step guide with screenshots and tips.
Read guide →Step-by-step guide with screenshots and tips.
Read guide →Step-by-step guide with screenshots and tips.
Read guide →Step-by-step guide with screenshots and tips.
Read guide →