About JWT Decoder
This JWT decoder splits a JSON Web Token at its dots and shows the decoded header and payload as formatted JSON. Paste the token, with or without a leading Bearer prefix, and you can read the algorithm, the claims such as sub, iss and aud, and the exp, iat and nbf times. The status line tells you whether the token has expired.
Important: this tool only decodes the token. It does not verify the signature, so a decoded token is not proof that it is genuine or untampered. Verification needs the secret or public key and belongs on your server. Decoding runs in your browser and the token is not uploaded, but avoid pasting live production tokens into any website.
How to use JWT Decoder
- 01
Paste your JWT.
- 02
Read the decoded header and payload.
- 03
Check the expiry status.
When to use it
- Checking why an API returns 401 by looking at the exp claim of the token.
- Reading the roles, scopes or user id stored in an access token.
- Confirming which algorithm and key id a token header declares.
- Comparing the iss and aud claims with what your backend expects.
- Inspecting a token from a test environment while debugging authentication.
Frequently asked questions
Does this tool verify the JWT signature?
No. It only decodes the header and payload, which are plain Base64URL-encoded JSON. To verify a signature you need the secret or public key, and the check should be done in your own server code.
Is it safe to paste my JWT here?
Decoding runs in your browser and nothing is uploaded to i40x. Even so, a valid token can grant access, so prefer test tokens and avoid pasting live production tokens into any website.
Can anyone read the contents of a JWT?
Yes. A normal signed JWT is encoded, not encrypted, so anyone holding it can read the payload. Do not store passwords or other secrets in the claims.
How do I know if my token has expired?
If the payload contains a numeric exp claim, the tool compares it with the current time and shows the token as expired or valid. The exp, iat and nbf values are also displayed as readable dates.
What does Could not decode this token mean?
The text is not a complete JWT. It needs at least a header and a payload separated by a dot, each Base64URL-encoded JSON. Check for missing characters, extra quotes or a truncated copy.
Can it decode encrypted JWE tokens?
No. It reads signed tokens whose header and payload are Base64URL-encoded JSON. Encrypted tokens cannot be read without the decryption key and are not supported.