Skip to content
QZTools

Decode a JWT

Inspect an auth token's contents without sending it anywhere.

Everything runs in your browser. Nothing you type or paste is sent to a server.

How to decode a JWT

  1. 1

    Paste the JWT (with or without “Bearer”).

  2. 2

    Review the decoded header and payload.

  3. 3

    Check the issue and expiry dates.

About this tool

A JWT has three Base64URL parts: header, payload and signature. This tool decodes the first two and converts dates (exp, iat, nbf) to your local time.

Tokens grant access to accounts, so they shouldn't be pasted into services that send them to a server. Here everything happens in your browser.

Frequently asked questions

Does it verify the signature?

No. Verifying requires the issuer's key. We only decode the contents.

Is it safe to paste a real token?

The token never leaves your device. Still, avoid sharing live tokens with other people.