JWT decoder

Read header, payload and expiry

No database: AIMRAN doesn't store your files, text or results

What is JWT decoder?

A JWT (JSON Web Token) is a token many applications use to identify a user after logging in. It looks like an unreadable string, but it actually contains JSON data that this tool displays clearly.

Paste the token and you'll see its header, its contents and whether it has expired. If you know the secret key, you can also check that the signature is authentic.

How to use it

  1. Paste the JWT into the “Token” field, with or without the Bearer prefix.
  2. Review the header, the payload and the expiration status.
  3. Check under “Dates” when it was issued, when it becomes valid and when it expires.
  4. To verify the signature, enter the HMAC secret and indicate whether it's Base64.

Advantages

Technical details

The token is split into its three parts (RFC 7519), and the header and payload are decoded from Base64URL and parsed as JSON; the Bearer prefix is removed automatically. Five-part JWE tokens are detected and flagged as encrypted. The iat, nbf, exp and auth_time claims (Unix seconds) are shown as dates and compared with the current time to indicate whether the token is valid, expired or not yet valid. A warning is shown if alg is “none”. The HMAC signature is verified with the Web Crypto API (crypto.subtle.verify) over “header.payload” with SHA-256, SHA-384 or SHA-512 depending on the algorithm; the key can be entered as text or Base64. Asymmetric algorithms (RS, ES, PS) are decoded but not verified.

Frequently asked questions

What is a JWT?

A compact token with three dot-separated parts: header, payload (data) and signature. It's used for authentication and authorization in APIs and web applications.

How do I know if a JWT has expired?

Look at the exp claim in the payload. The tool converts it to a date and tells you whether the token is still valid or how long ago it expired.

Is decoding a JWT the same as verifying it?

No. Anyone can read the contents of a JWT. Verifying it means checking the signature with the key to make sure it hasn't been modified.

Can I verify RS256 tokens?

The tool decodes any JWT, but only verifies HMAC signatures: HS256, HS384 and HS512.

Is it safe to store sensitive data in a JWT?

Not in a regular signed JWT (JWS), because its payload is only Base64URL-encoded and can be read. JWE is used to hide data.

More Developers tools