Technology & Developers
Free JWT Decoder
Paste a JWT to see its header and payload, check its expiry, and optionally verify its signature - entirely in your browser.
Free to useNo sign-up requiredNo watermarkRuns in your browser
A JSON Web Token is three base64url-encoded parts separated by dots: a header, a payload and a signature. The header and payload are not encrypted - they are just encoded - so anyone holding the token can already read them. What this tool does is decode those two parts back into readable JSON, check the expiry claim, and optionally verify an HMAC signature if you provide the secret.
A production auth token can carry a user ID, an email address, roles or other claims. It is worth being deliberate about where you paste one to inspect it - this tool decodes it entirely in your browser, with nothing sent to a server.
How this tool works
Paste the token
The full three-part JWT string, exactly as issued.
Read the header and payload
Both are decoded and pretty-printed, and the expiry claim (if present) is checked against the current time.
Verify the signature (optional)
For an HS256, HS384 or HS512 token, enter the shared secret to confirm the signature is valid and the token has not been tampered with.
How it works
The header and payload segments are base64url-decoded and parsed as JSON directly in your browser - this is standard decoding, not decryption, and requires no key.
The expiry check compares the payload's "exp" claim (if present) against the current time and states plainly whether the token is expired.
Signature verification, when you provide a secret, uses the HMAC algorithm named in the token's header to recompute the signature and compare it - the same check a server performs when it validates a token.
Decoding is not the same as verifying
Anyone can decode a JWT's header and payload without any key at all - that is by design, since a JWT is meant to be readable, only its signature protects it from being altered undetected. Seeing a token's contents does not mean it is genuine. Only verifying its signature against the correct key confirms that.
What this tool can and cannot verify
- HS256, HS384 and HS512 (HMAC, shared-secret) signatures can be verified if you provide the secret.
- RS256/RS384/RS512 (RSA) and ES256/ES384/ES512 (elliptic curve) tokens are signed with a public/private key pair rather than a shared secret, and are not supported for verification in this version.
- A token can always be decoded and read, regardless of whether its signature can be verified.
Worked examples
An expired token
If the payload's "exp" claim is in the past, the tool marks the token as expired rather than requiring you to convert the timestamp yourself.
A tampered payload
Changing even one character of a valid token's payload will make signature verification fail, which is exactly the property a JWT is designed to have.
Frequently asked questions
Is it safe to paste a real token here?
Decoding happens entirely in your browser - the token is never sent to VSThiran or anywhere else. That said, treat any tool you paste a production token into with the same caution: prefer one that is transparent about processing everything locally, which is what this one does.
Can this tool see my token?
No. There is no network request involved in decoding or verifying - everything happens with JavaScript running in your own browser tab.
What does "exp" mean and why is my token expired?
"exp" is the expiry claim, a Unix timestamp after which the token should no longer be accepted. Tokens are commonly issued with short lifetimes (minutes to a few hours) for security, so an expired token usually just means it is time to sign in again or refresh it.
Why can't this verify my RS256 token?
RS256 and other RSA/EC algorithms verify against a public key, not a simple shared secret, and supporting that safely needs a way to enter a full public key or JWK - not yet built into this version. The token can still be decoded and read either way.
Why does my signature verification fail with the correct secret?
Check for extra whitespace or line breaks pasted along with the token or secret, and confirm the algorithm shown in the decoded header matches the one your server actually used to sign it.
Guides for this tool
Is it safe to decode a JWT online?
What decoding a JWT online actually does with your token, why a production auth token deserves caution, and how to check whether a decoder tool is genuinely processing it locally.
How to check if a JWT is expired
What the "exp" claim in a JWT means, how to check it without writing code, and what to do once you know a token has expired.
