What it does
Decodes a
JSON Web TokenJSON Web TokenA compact, URL-safe token that carries claims (like identity or expiry) between two parties, signed to prevent tampering.Learn more
and shows what is inside — locally, in your browser. Paste a JWT and the header and payload open as pretty-printed JSON in side-by-side panes, withalg and typ chips above them. Under those chips sit up to three security notices: alg none — unsigned token (red, for alg: none), symmetric — verify server-side (info, for HS256/HS384/HS512), and no exp claim (accent, when the payload carries no expiry). Time claims (exp, iat, nbf) render humanized — exp in 43 days, iat 2 hours ago — and the payload pane carries a valid or expired badge driven by exp.
This tool decodes only — it never verifies a signature. Verifying a signature needs the secret or public key, which lives server-side, so every claim you read here is an assertion by the sender, not a verified fact.
How to use it
- Pick a sample chip — HS256, Expired, alg: none — or paste your own token into the
JWTJWTA compact, URL-safe token that carries claims (like identity or expiry) between two parties, signed to prevent tampering.Learn more
box. A token has three dot-separated parts; fewer than two parts draws an error box. - Read the panes: Header (algorithm metadata) left, Payload (the claims) right. Copy either as JSON.
- Scan the notice chips: they flag unsigned tokens, symmetric algorithms, and missing expiry at a glance.
- Check the badge next to Payload:
validwhileexplies in the future,expiredonce it passes. - Copy a share link that carries the token in the URL, or read the raw signature shown under the panes.
Examples
The HS256 chip fills the token eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkFkYSBMb3ZlbGFjZSIsImlhdCI6MTcwMDAwMDAwMH0.sig (dummy signature). It decodes to:
| Part | Decoded |
|---|---|
| Header | { "alg": "HS256", "typ": "JWT" } |
| Payload | { "sub": "1234567890", "name": "Ada Lovelace", "iat": 1700000000 } |
Its payload has no exp, so the notices read symmetric — verify server-side and no exp claim.
The Expired chip carries exp: 1700000000 (2023-11-14T22:13:20Z) plus an iat one second earlier — both in the past — so the payload badge reads expired and the humanized chip reads exp 1015 days ago (the count grows with time; the badge does not change back).
The alg: none chip is eyJhbGciOiJub25lIn0.eyJzdWIiOiIxIn0. — header { "alg": "none" }, payload { "sub": "1" }, empty signature after the trailing dot. It decodes like any other token and draws the red alg none — unsigned token notice plus no exp claim; the signature line shows (none).
A two-part token such as eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxIn0 (header and payload, no third segment) still decodes — the missing signature renders as (none). Input with fewer than two dot-separated parts, like abc, draws the error box: A JWT has 3 dot-separated parts: header.payload.signature.
Good to know
- A
JWTJWTA compact, URL-safe token that carries claims (like identity or expiry) between two parties, signed to prevent tampering.Learn more
is three base64url parts joined by dots:header.payload.signature. Base64url swaps+→-and/→_and drops=padding so a token can sit inside a URL or HTTP header — which is why aJWTJWTA compact, URL-safe token that carries claims (like identity or expiry) between two parties, signed to prevent tampering.Learn more
never contains+,/, or=. - The signature is computed over
base64url(header) + "." + base64url(payload)using the header’s algorithm —HMACHMACA construction that combines a hash function with a secret key to prove a message is intact and came from someone holding the key.
with a shared secret (HS256) or a private key (RS256). Change one byte of either encoded part and it no longer matches. Anyone can write any header and payload they like; the signature is the only part nobody can forge without the key. That is exactly why this tool decodes but never verifies. - Time claims are Unix seconds:
iat= issued at,nbf= not valid before,exp= expires. A missing third segment renders as(none); two-part tokens still decode. - Private: decoding runs locally in your browser. A
JWTJWTA compact, URL-safe token that carries claims (like identity or expiry) between two parties, signed to prevent tampering.Learn more
is often a live credential — this tool never transmits it. (The share link you copy does carry the token; share only tokens you control.) - Related tools:
HMACHMACA construction that combines a hash function with a secret key to prove a message is intact and came from someone holding the key.
Generator, JSON Formatter,Base64Base64An encoding representing binary data as 64 safe ASCII characters, so it survives transport through text-only channels. It encodes — it does not encrypt.
Encode / Decode.
Snippets for JWT Debugger
This task as a runnable recipe — same job, every language, copy-ready.