Skip to content
toolsdocks

Decode and inspect a JWT

Paste a JSON Web Token to read its header and claims and check its time claims. The token is decoded on this page and is not sent anywhere.

Runs on your device
Loading tool…

How to use

  1. Paste the token. It never leaves this page.
  2. Read the header, payload and claim times.
  3. Optionally paste a secret or public key to verify the signature.

Worked example

A payload with "exp": 1767225600 shows “Expires 1 Jan 2026, 00:00 UTC” and whether that is in the past.

Supported formats and limits

InputJWT (JWS compact), Secret, PEM or JWK for verification
OutputHeader, payload, claims
EngineBase64URL decoding; jose for signature verification

Limitations

  • Decoding does not prove a token is genuine; only signature verification with the right key does.
  • A valid signature does not check the issuer, audience or other claims your application relies on.
  • Encrypted tokens (JWE) cannot be decoded without the key; only their header is shown.

Questions

Does decoding a JWT prove it is valid?

No. Anyone can create a token with any claims, and the header and payload are only Base64URL-encoded JSON. Only verifying the signature with the issuer's secret or public key shows it was signed by that key, and your application must still check claims such as issuer and audience.

Which keys can verify a signature?

A shared secret for HS256, HS384 and HS512, or a public key as PEM (SPKI or X.509 certificate), JWK or JWK Set for RS, PS, ES and EdDSA algorithms. Only the algorithm in the token header is accepted.

How are expiry times shown?

exp, nbf, iat and similar claims are shown as dates in your device's time zone with a relative time, and the token is marked expired, not yet valid or current against your device clock. An exp of 1767225600 is 1 Jan 2026, 00:00 UTC.

Privacy

Runs on your device. Files and text are processed in this browser tab and are not uploaded.

See the privacy policy for how toolsdocks handles data.