JWT Decoder

Paste a JWT to decode its header and payload, see issued-at and expiry times in your time zone, and check whether the token has expired. Decoded locally — tokens never leave your browser.

header
{
  "alg": "HS256",
  "typ": "JWT"
}
payload
{
  "sub": "1234567890",
  "name": "Dhruv Agrawat",
  "role": "admin",
  "iat": 1700000000,
  "exp": 1900000000
}
Expires (exp)3/17/2030, 5:46:40 PM
Issued at (iat)11/14/2023, 10:13:20 PM

Signature (22 chars) is not verified — verify tokens on your server with the secret or public key.

Frequently asked questions

Is it safe to paste my token here?

Decoding happens entirely in your browser — the token is never sent anywhere. Still, treat production tokens like passwords and avoid sharing them.

Does this verify the signature?

No. It decodes the header and payload, which are only Base64URL-encoded. Verifying the signature requires the secret or public key and should happen on your server.

What do exp, iat and nbf mean?

exp is the expiry time, iat is when the token was issued, and nbf is 'not before'. All are Unix timestamps in seconds; the decoder shows them as readable dates.

Theme