Best Free JWT Decoder
Decode a JWT header and payload in your browser, with exp/iat as dates - no upload, no signature verification.
How it works
- Paste the token. Drop a JWT (the eyJ… string) into the input box.
- Decode it. Click Decode to pretty-print the header and payload as JSON.
- Read the claims. Check exp/iat as human dates. Everything stays in your browser; the signature is not verified.
About this tool
Paste a JSON Web Token and instantly read what is inside it. The decoder splits the token on its dots, Base64url-decodes the header and payload, and pretty-prints both as JSON. Timestamp claims like iat, nbf and exp are shown as human-readable dates, with exp flagged as expired or valid. Crucially, this tool only DECODES the token locally to inspect it - it does NOT verify the signature and nothing is ever sent to a server, so it is safe to paste a token while debugging auth. The signature segment is shown as-is, clearly marked unverified.
What people use it for
- Inspect the claims inside an auth token while debugging
- Check a token expiry (exp) and issued-at (iat) dates
- See which algorithm and headers a JWT uses
- Read a custom payload field without a server round-trip