mAIbmAIbTools

JWT Decoder

Decode a JWT to inspect its header, payload and expiry — entirely in your browser.

Header
Payload

How to use

  1. Paste your JWT.
  2. The header and payload are decoded and pretty-printed.
  3. If there's an expiry claim, you'll see whether the token is still valid.

How the JWT Decoder works

Decodes a JSON Web Token so you can read its header and claims — essential when debugging authentication that is failing for reasons the error message will not tell you.

A JWT is three Base64url-encoded segments joined by dots: header, payload and signature. This tool decodes the first two and displays them as formatted JSON. Registered claims such as exp and iat are Unix timestamps.

header.payload.signature (each segment Base64url-encoded)

Worked example

A payload might decode to {"sub":"1234567890","name":"Jane","iat":1516239022,"exp":1516242622} — issued and expiring an hour apart.

Things worth knowing

Frequently asked questions

Does this verify the signature?

No — decoding only reveals the contents. Verifying the signature needs the secret or public key, which stays on your server.

Is my token sent anywhere?

No — decoding happens entirely in your browser, so your token is never transmitted.

Why is my token rejected even though it looks correct?

Most often expiry — check the exp claim against current time — or a clock skew, audience or issuer mismatch.

Is it safe to paste a real token here?

It is decoded locally and never leaves the page. Still, treat production tokens as live credentials and rotate anything you have shared elsewhere.