go-supertools
Developer & Data Tools

JWT Decoder

Decode a JSON Web Token to read its header and payload.

Runs in your browser Your input never leaves your device.

0 characters | 0 words
—

About this tool

Paste a JSON Web Token to read its header and payload as formatted JSON. If the payload has an exp claim, the tool shows the expiry date and whether the token has expired. The decoding runs in your browser, so the token is not sent anywhere. This tool only decodes: it does not create tokens and it does not verify the signature, because verifying requires the secret or public key. A decoded token is readable by anyone, so never treat the contents as private.

How to use it

  1. Paste the full token (three parts separated by dots).
  2. Read the header and payload shown below.
  3. Check the Expires line if the token has an exp claim.

Example

Input
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
Result
HEADER:
{
  "alg": "HS256",
  "typ": "JWT"
}

PAYLOAD:
{
  "sub": "1234567890",
  "name": "John Doe",
  "iat": 1516239022
}

Signature: SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c — not verified (no secret).

Common problems

"Not a JWT" message
A JWT has dots between its parts (header.payload.signature). Remove any "Bearer " prefix and surrounding quotes.
"Invalid Base64URL in token"
The header or payload is cut off or contains characters that are not valid in a token. Copy the whole token again.
Token decodes but you need to know if it is genuine
Decoding does not prove authenticity. Signature verification must be done on your server with the key.

Frequently asked questions

Can this create or sign a JWT?

No. It only decodes. Signing needs a secret or private key, which this tool does not handle.