// Paste a JWT to decode
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkphbmUgRG9lIiwiaWF0IjoxNzA1MzEwOTAwLCJleHAiOjE5OTk5OTk5OTl9.dQw4w9WgXcQStart typing to search, or pick a tool.
Decode the header, payload, and signature of a JSON Web Token. Decoding is local — your token is never sent to a server.
JWT
Decoded
// Paste a JWT to decode
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkphbmUgRG9lIiwiaWF0IjoxNzA1MzEwOTAwLCJleHAiOjE5OTk5OTk5OTl9.dQw4w9WgXcQNo. Decoding only reads the header and payload — it does not check the signature or prove authenticity. Always verify tokens on the server.
No. Decoding runs entirely in your browser. Do not paste tokens you do not own into third-party services.
The JWT spec defines standard claims like iss (issuer), sub (subject), aud (audience), exp (expiration), nbf (not before), iat (issued at), and jti (token id).
The exp claim is a Unix timestamp in seconds. We compute the expiration date and check whether the token is expired.