JWT Decoder
Paste a JWT to read its header and payload and see its expiry as a date.
Decoding is not signature verification. Anyone can read the contents of a JWT, so never put secrets in it.
JWT
Header
Payload
Signature
| Base64URL | — | |
|---|---|---|
| Length | — | |
| Algorithm (alg) | — |
The secret is used only in this browser and is not stored.
How to use JWT Decoder
- 1Paste a JWT into the input panel, or press Sample. A leading Bearer prefix is fine.
- 2Read the header, the payload, and the exp, nbf, and iat dates. Change the time zone to change how the dates are shown.
- 3Press Copy to copy the header or the payload, or Download to save the payload as a .json file.
JWT Decoder options
- Time zone
- The time zone used for the exp, nbf, and iat dates: Browser (default), UTC, KST, or JST. The browser time zone is written as its offset from UTC, such as UTC+09:00.
- Secret for HS256 / HS384 / HS512 verification
- Type the secret to compute the HMAC signature and see Signature matches or Signature does not match. The secret is not stored. Public-key algorithms such as RS256 and ES256 are not verified.
How a JWT is built
A JWT is the token format defined in RFC 7519, and the common signed form (JWS) is defined in RFC 7515. It has three parts separated by dots, header.payload.signature, and each part is Base64URL without padding. The header holds the signing algorithm (alg) and the payload holds the claims (sub, exp, and so on), both as JSON.
exp (expiry), nbf (not before), and iat (issued at) are seconds counted from 1970-01-01 00:00:00 UTC. This tool turns those values into dates in the time zone you choose and compares them with the current time. A token has expired when the current time is equal to or later than exp.
Decoding is not verification
Decoding is not signature verification. Anyone can read the contents of a JWT, so never put secrets in it. The header and the payload are not encrypted. They are JSON written in Base64URL, so anyone who sees the token can read them without a key.
The signature is what shows that the contents were not changed. HS256, HS384, and HS512 are HMAC algorithms (RFC 7518) that sign and check with one shared secret, so when you type the secret this browser can compute whether the signature matches. In a real service the server has to check the signature together with exp, the issuer (iss), and the audience (aud).
JWT Decoder examples
Header of a token with a Bearer prefix
You can paste an Authorization header value as is. Bearer and the surrounding whitespace are removed.
Input
Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IlpFS0lMTyIsImlhdCI6MTc2NzIyNTYwMCwiZXhwIjoxNzY3MjI5MjAwfQ.218DR4r7DRNkKO3XJcQYXE0ztwbqxYMeQpkIp9S18oE
Output
{ "alg": "HS256", "typ": "JWT" }Payload of the same token
iat 1767225600 is 2026-01-01 00:00:00 UTC and exp 1767229200 is 2026-01-01 01:00:00 UTC. As of 2026-10-02 this token has expired.
Input
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IlpFS0lMTyIsImlhdCI6MTc2NzIyNTYwMCwiZXhwIjoxNzY3MjI5MjAwfQ.218DR4r7DRNkKO3XJcQYXE0ztwbqxYMeQpkIp9S18oE
Output
{ "sub": "1234567890", "name": "ZEKILO", "iat": 1767225600, "exp": 1767229200 }Check the signature with the secret (HS256)
With the secret zekilo-secret. A different secret, such as wrong, gives Signature does not match.
Input
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IlpFS0lMTyIsImlhdCI6MTc2NzIyNTYwMCwiZXhwIjoxNzY3MjI5MjAwfQ.218DR4r7DRNkKO3XJcQYXE0ztwbqxYMeQpkIp9S18oE
Output
Signature matches
Input that is not a JWT
Input
abc.def
Output
Found 2 part(s) separated by dots. A JWT has three.
Examples use the reference cases this tool is tested against.
JWT Decoder: frequently asked questions
Is my input sent to a server?
No. Your input and the result are processed only in this browser and are not stored. Reloading the page clears them.
If a token decodes, does that mean it is valid?
No. Decoding is not signature verification. Anyone can read the contents of a JWT, so never put secrets in it. The header and the payload are only written in Base64URL, so they can be read without any key. Whether a token can be trusted is for the server to decide by checking the signature, exp, and the other claims.
How do I see when a token expires?
The exp claim in the payload is the expiry time. This tool turns the exp, nbf, and iat numbers (seconds since 1970-01-01 UTC) into dates. If exp has passed it shows Expired with how long ago, and if nbf is still in the future it shows Not valid yet.
What does the no signature warning mean?
When alg in the header is none, the token has no signature. There is no way to check who wrote it or whether it was changed on the way, so a server should not accept such a token.
Can it verify RS256 or ES256 tokens, or create tokens?
Signature verification supports only HS256, HS384, and HS512, which use a shared secret. Tokens signed with public-key algorithms such as RS256 and ES256 can be read but not verified here. The tool does not create tokens or sign them again.
Why does it say Not a JWT?
A JWT has three parts separated by dots, header.payload.signature, and each part is Base64URL. If there are not three parts, or a part contains a character that is not Base64URL, you get an error. Encrypted tokens (JWE, five parts) cannot be read without the key, so they are not decoded.
Related tools
How it works · Standards
- Processed in: this browser (your device). Nothing is sent or stored.
- Standards: RFC 7519 · RFC 7515
- Engine: ZEKILO Dev Base64URL decoder and JSON printer (in-house code) · Web Crypto API (HMAC signature verification) (built into the browser)
- Numbers in the header and the payload are shown exactly as written. Large integers are not changed.
- A token counts as expired when the current time is equal to or later than exp.
- The secret is read as UTF-8 text.
- As of 2026.10.03
- Changelog: 2026.10.03 First release