Skip to content
TNToolsNexus

JWT decoder

Decode a JWT's header and payload, humanize exp/iat/nbf with an expired verdict — locally, with the decode-is-not-verify warning up front.

Decoding is not verification. This shows what the token claims — it does not check the signature, so never treat a decoded token as trusted input.

Tokens are decoded on your device — nothing is sent anywhere, which is the only acceptable way to inspect a JWT.

Paste a JWT and read it: header, payload, algorithm, and the time claims turned into real dates — with an unmissable EXPIRED / still-valid verdict on exp, and the honest banner every decoder should carry: decoding is not verification.

How to decode a JWT

  1. Paste the token — decoding is instant and local.
  2. Read the verdict chips: algorithm, expiry (with EXPIRED status), issued-at, not-before.
  3. Inspect the pretty-printed header and payload; copy the payload JSON if you need it.

What a decoder is actually for

Nine times out of ten: why did this request get a 401? The answer is in the claims — the token expired an hour ago, the aud doesn’t match, the sub is the wrong user, the clock skew put nbf in the future. A decoder turns the opaque eyJ… blob into those answers in seconds. The header tells you the algorithm your verifier must expect; a missing signature part or "alg": "none" tells you something is very wrong.

The line this tool won’t blur

JWTs are readable by design — base64url is encoding, not encryption — which means anyone can decode one; the security lives entirely in the signature that this tool does not and cannot check. Never make an authorization decision from decoded claims, and never assume a token is genuine because it parses. (That base64url layer is the same one in the Base64 tool; raw timestamps convert in the timestamp converter, and the payload prints nicely in the JSON formatter.)

Private by design

Tokens are credentials. This decoder runs entirely on your device — the token never travels, which is the one property a JWT tool must have.

Last updated:

Frequently asked questions

Does this verify the token's signature?
No — and no purely client-side decoder can, without your secret or public key. Decoding shows what the token CLAIMS; verification proves who signed it. This tool is for reading and debugging, and it says so on the page rather than implying safety it can't provide.
Is it safe to paste a real production token here?
Safer here than most places, because nothing leaves your browser — the classic JWT-debugger risk is exactly that pasted production tokens hit someone's server. Still, treat live tokens like passwords: prefer expired or staging tokens when debugging with anyone watching.
What do exp, iat, and nbf mean?
Registered claims, all Unix timestamps: exp = expires at, iat = issued at, nbf = not valid before. The tool converts each to an ISO date and stamps exp with a clear EXPIRED / still-valid verdict — the single most common thing people open a decoder to learn.
Why does my token only have two parts?
A JWT is header.payload.signature; a missing third part usually means alg "none" or a truncated copy-paste. The tool decodes it anyway and flags the missing signature loudly, because unsigned tokens deserve suspicion.
Is my token stored or sent anywhere?
No. Splitting, base64url-decoding, and JSON parsing all run in your browser — nothing is transmitted or logged.

Related tools

Base64 Encode / Decode

Encode text to Base64 and decode it back — Unicode-safe, URL-safe variant included, instant, and nothing leaves your browser.

JSON Formatter

Format, validate, and minify JSON as you paste — 2/4-space or tab indentation, clear syntax errors, copy or download. Private.

Unix Timestamp Converter

Unix timestamp to date and back — seconds or milliseconds auto-detected, UTC + local + relative views, and a Now button.