How to use the JWT Decoder
- Paste the token (with or without “Bearer”).
- Read the decoded header and payload.
- Check the issued and expiry times.
What does this tool do?
A JWT has three Base64URL-encoded parts separated by dots: a header (algorithm and type), a payload (claims such as user ID and expiry) and a signature. Anyone can read the first two parts — that's what this tool does.
The signature proves the token wasn't tampered with, but checking it needs the secret or public key, so it's not verified here.
Why use it?
- Debug authentication problems.
- Check expiry and scopes quickly.
- Decoded locally — tokens aren't sent anywhere.
Common claims
iss (issuer), sub (subject/user), aud (audience), exp (expiry), iat (issued at) and nbf (not before). Times are Unix timestamps in seconds.
Accuracy and limits
- Treat live tokens like passwords. Even though decoding happens locally, avoid pasting production tokens into any website you don't trust.
Privacy
Everything you type is processed in your browser. Nothing you enter is sent to our servers or stored by us. There's no account to create and nothing to install.
Last reviewed by the M2Toolkit team.