JWT

JWT Decoder

Read JWT claims and time fields without signature verification

Security & Auth
🔒 100% client-side — your data never leaves this page
Maintained by Evan•Updated: September 30, 2026
Options
Input

Paste a JWT to inspect header, payload, and exp / iat; signature notes and diagnostics are available in Advanced mode.

🔒 Local decoding · No saved token draft
Output
Decoded JWT will appear here
Page reading mode

The full guide also includes pitfalls, worked examples, snippets, FAQs, and related tools for checking results or troubleshooting.

About this tool

Paste a three-part compact JWT, optionally with a Bearer prefix, to read its Header and Payload JSON objects and inspect the encoded Signature segment. The tool compares exp and nbf with your device clock and shows NumericDate values in UTC. It does not verify signatures, issuer, audience, permissions, or server acceptance. Token input is not uploaded or saved as a browser draft; legacy token drafts are removed when the page opens.

Suggested Workflow

Production Snippets

Read a public unsigned sample without treating it as authentication

text

Header: {"alg":"none","typ":"JWT"}
Payload: {"sub":"demo","exp":59}
Token: eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.eyJzdWIiOiJkZW1vIiwiZXhwIjo1OX0.
At Unix time 59: Expired · Unverified
The final dot marks an empty signature.

Frequently Asked Questions

Does a decoded token prove that authentication will succeed?

No. Every parsed result remains unverified. Anyone can write claims and attach a fake signature. This tool does not take a verification key or enforce issuer, audience, permissions, or the receiving service’s policy.

Which JWT structures are supported?

Three dot-separated segments with unpadded Base64url Header and Payload that decode to UTF-8 JSON objects. The encoded signature is displayed; an empty signature can be inspected. Five-part encrypted JWE, unencoded JWS payloads, arrays, damaged UTF-8, and internal whitespace are rejected. An outer Bearer prefix and surrounding whitespace are accepted.

When is exp considered expired?

At or after exp: the device’s current Unix time must be strictly less than exp. nbf indicates the earliest permitted time. These local comparisons have no clock-skew allowance and do not prove the signature is valid. A missing exp is reported without inventing a lifetime.

Why does a time claim show invalid or outside date range?

exp, nbf, and iat should be numeric seconds since the Unix epoch, not millisecond timestamps or date strings. Non-numeric values and dates outside JavaScript’s representable range are flagged rather than crashing the display. A millisecond value can still form a very distant date, so check the units.

Is my token uploaded or retained as a draft?

The decoder does not upload token contents or save a token draft. It removes the previous version’s localStorage draft when opened. Clipboard copies and browser extensions are outside this draft control; use synthetic or redacted tokens for demonstrations.

How should I interpret the example tokens?

They have readable synthetic claims and a placeholder signature. “Not expired” describes only the exp comparison. The examples are not signed credentials, and changing an expired claim does not refresh or authenticate a real token.

Keep browsing