How to use the JWT Decoder
- Paste the token (with or without “Bearer”).
- Read the decoded header and payload.
- Check the issued and expiry times.
What does this tool do?
A JWT has three Base64URL-encoded parts separated by dots: a header (algorithm and type), a payload (claims such as user ID and expiry) and a signature. Anyone can read the first two parts — that's what this tool does.
The signature proves the token wasn't tampered with, but checking it needs the secret or public key, so it's not verified here.
Why use it?
- Debug authentication problems.
- Check expiry and scopes quickly.
- Decoded locally — tokens aren't sent anywhere.
Common claims
iss (issuer), sub (subject/user), aud (audience), exp (expiry), iat (issued at) and nbf (not before). Times are Unix timestamps in seconds.
Accuracy and limits
- Treat live tokens like passwords. Even though decoding happens locally, avoid pasting production tokens into any website you don't trust.
Privacy
Everything you type is processed in your browser. Nothing you enter is sent to our servers or stored by us. There's no account to create and nothing to install.
Frequently asked questions
Can I read a JWT without the secret key?
Yes. The header and payload are only Base64URL-encoded, not encrypted, so anyone with the token can read them. The secret or public key is only needed to verify the signature.
Is it safe to paste a real token here?
Decoding happens in your browser and the token isn't sent anywhere. Even so, a valid token works like a password until it expires, so prefer expired or test tokens and never share live ones.
Last reviewed by the M2Toolkit team.