π JWT Decoder β Header and Payload
Paste a JWT to inspect its header and claims locally. Nothing is uploaded. Signature verification is intentionally not performed.
How it works
- Paste a token with three base64url segments separated by dots.
- Press Decode. The header and payload are decoded and formatted as JSON when possible.
- Read the claim timestamps if present. The signature segment is shown only as a length, not verified.
Examples
- A token whose payload includes exp shows that claim as a Unix time and a local date.
- A two-segment string is rejected because a JWT has header, payload and signature.
- Payloads that are not JSON are shown as decoded text instead of formatted JSON.
Frequently asked questions
Does this verify the signature?
No. Decoding only reveals what the token claims. Trust a token only after a server verifies it with the correct key.
Is the token uploaded?
No. Decoding uses the browser only. Still avoid pasting production secrets into a shared or logged machine.
What is the exp claim?
exp is the expiry time as seconds since 1970-01-01 UTC. iat is issued-at and nbf is not-before, when those claims exist.
Related tools
More Security tools βSHA-256 Hash Generator
Compute a SHA-256 hex digest of text entirely in the browser.
Background Remover
Remove the background from a photo and save a transparent PNG β free, private, no sign-up.
QR Code Generator
Make QR codes for links, Wi-Fi, UPI, WhatsApp and more β free PNG and SVG downloads.
Passport Photo Maker
Crop passport, visa and exam-form photos to size, limit the file size in KB and print a copy sheet β free.