Skip to content
M2TOOLKIT

Developer · free tool

JWT Decoder

Read the header and payload of a JSON Web Token and check when it expires.

Use it as often as you like — it's free, with no sign-up and no limits.

  • Developer
  • Free
  • No sign-up
  • Runs in your browser
  • Updated
Decoding only reads the token — it doesn't verify the signature. Never trust a token's contents on a server without verifying it.

Everything you type is processed in your browser. Nothing you enter is sent to our servers or stored by us.

How to use the JWT Decoder

  1. Paste the token (with or without “Bearer”).
  2. Read the decoded header and payload.
  3. Check the issued and expiry times.

What does this tool do?

A JWT has three Base64URL-encoded parts separated by dots: a header (algorithm and type), a payload (claims such as user ID and expiry) and a signature. Anyone can read the first two parts — that's what this tool does.

The signature proves the token wasn't tampered with, but checking it needs the secret or public key, so it's not verified here.

Why use it?

  • Debug authentication problems.
  • Check expiry and scopes quickly.
  • Decoded locally — tokens aren't sent anywhere.

Common claims

iss (issuer), sub (subject/user), aud (audience), exp (expiry), iat (issued at) and nbf (not before). Times are Unix timestamps in seconds.

Accuracy and limits

  • Treat live tokens like passwords. Even though decoding happens locally, avoid pasting production tokens into any website you don't trust.

Privacy

Everything you type is processed in your browser. Nothing you enter is sent to our servers or stored by us. There's no account to create and nothing to install.

Frequently asked questions

Can I read a JWT without the secret key?

Yes. The header and payload are only Base64URL-encoded, not encrypted, so anyone with the token can read them. The secret or public key is only needed to verify the signature.

Is it safe to paste a real token here?

Decoding happens in your browser and the token isn't sent anywhere. Even so, a valid token works like a password until it expires, so prefer expired or test tokens and never share live ones.

Last reviewed by the M2Toolkit team.

Other tools people use alongside the jwt decoder.