Decode a JWT
Inspect an auth token's contents without sending it anywhere.
Everything runs in your browser. Nothing you type or paste is sent to a server.
How to decode a JWT
- 1
Paste the JWT (with or without “Bearer”).
- 2
Review the decoded header and payload.
- 3
Check the issue and expiry dates.
About this tool
A JWT has three Base64URL parts: header, payload and signature. This tool decodes the first two and converts dates (exp, iat, nbf) to your local time.
Tokens grant access to accounts, so they shouldn't be pasted into services that send them to a server. Here everything happens in your browser.
Frequently asked questions
Does it verify the signature?
No. Verifying requires the issuer's key. We only decode the contents.
Is it safe to paste a real token?
The token never leaves your device. Still, avoid sharing live tokens with other people.
Related tools
- Images
Favicon Generator
Create favicon.ico and every icon your site needs from an image or letters.
- Images
Image to Base64
Turn an image into Base64 or a data URI for HTML, CSS or JSON.
- Images
Base64 to Image
Decode Base64 or a data URI and download the image.
- Images
Image Color Picker
Get the HEX, RGB or HSL code of any point in an image.