Paste a JWT to decode its header and payload, see issued-at and expiry times in your time zone, and check whether the token has expired. Decoded locally — tokens never leave your browser.
{
"alg": "HS256",
"typ": "JWT"
}{
"sub": "1234567890",
"name": "Dhruv Agrawat",
"role": "admin",
"iat": 1700000000,
"exp": 1900000000
}(exp)3/17/2030, 5:46:40 PM(iat)11/14/2023, 10:13:20 PMSignature (22 chars) is not verified — verify tokens on your server with the secret or public key.
Decoding happens entirely in your browser — the token is never sent anywhere. Still, treat production tokens like passwords and avoid sharing them.
No. It decodes the header and payload, which are only Base64URL-encoded. Verifying the signature requires the secret or public key and should happen on your server.
exp is the expiry time, iat is when the token was issued, and nbf is 'not before'. All are Unix timestamps in seconds; the decoder shows them as readable dates.