JWT decoder
Paste a JSON Web Token to read its header and claims, with exp, iat and nbf shown as dates so you can see at a glance whether it has expired.
Runs in your browser — nothing you paste is sent to a server.
{
"alg": "HS256",
"typ": "JWT"
}{
"sub": "1234567890",
"name": "Ada Lovelace",
"iat": 1758600000,
"exp": 1758603600
}- exp—1758603600
- iat—1758600000
Signature not verified — decoding only.
Frequently asked questions
Is my token sent to a server or saved?
No. The token is decoded in your browser and is never sent anywhere or stored, not even in local storage. Close the tab and it is gone.
Why isn’t the signature verified?
Verifying a signature needs the issuer’s secret or public key, which you shouldn’t paste into a web page. Decoding only reads the Base64URL-encoded header and payload, so treat the claims as unverified until your server checks them.
What do exp, iat and nbf mean?
They are Unix timestamps in seconds. exp is when the token expires, iat is when it was issued, and nbf is the time before which it must not be accepted. The decoder shows each one as a date and time, and flags the token as expired once exp has passed.
Still have questions? Contact us
More free tools
Curl to code converter →
Paste a curl command — from your browser’s dev tools, an API reference or a teammate — and get the same request as Python, JavaScript, Go, Java, PHP, C# and more.
JSON to JSON Schema generator →
Paste a JSON sample, such as an API response, and get a JSON Schema that describes it — nested objects, arrays, required fields and common string formats.
Save requests, run tests and publish docs
apikumo keeps your requests in collections, runs them as test suites and publishes them as hosted docs — free for up to 3 members.
No card required · Sign in with Google, GitHub, or Discord