Free developer tool

JWT decoder

Paste a JSON Web Token to read its header and claims, with exp, iat and nbf shown as dates so you can see at a glance whether it has expired.

Runs in your browser — nothing you paste is sent to a server.

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkFkYSBMb3ZlbGFjZSIsImlhdCI6MTc1ODYwMDAwMCwiZXhwIjoxNzU4NjAzNjAwfQ.NqQBgFDJU38UWoRJI7sbOeZEc2k4dy1XQOO_uQnrKgk
Header
{
  "alg": "HS256",
  "typ": "JWT"
}
Payload
{
  "sub": "1234567890",
  "name": "Ada Lovelace",
  "iat": 1758600000,
  "exp": 1758603600
}
  • exp—1758603600
  • iat—1758600000

Signature not verified — decoding only.

FAQ

Frequently asked questions

Is my token sent to a server or saved?

No. The token is decoded in your browser and is never sent anywhere or stored, not even in local storage. Close the tab and it is gone.

Why isn’t the signature verified?

Verifying a signature needs the issuer’s secret or public key, which you shouldn’t paste into a web page. Decoding only reads the Base64URL-encoded header and payload, so treat the claims as unverified until your server checks them.

What do exp, iat and nbf mean?

They are Unix timestamps in seconds. exp is when the token expires, iat is when it was issued, and nbf is the time before which it must not be accepted. The decoder shows each one as a date and time, and flags the token as expired once exp has passed.

Still have questions? Contact us

More free tools

All free tools →

Save requests, run tests and publish docs

apikumo keeps your requests in collections, runs them as test suites and publishes them as hosted docs — free for up to 3 members.

No card required · Sign in with Google, GitHub, or Discord