ZYBERMART

JWT Decoder

Decode a JSON Web Token to read its header and claims, check when it expires, and verify HS256 signatures.


        

        

What's inside a JWT

A JSON Web Token has three parts separated by dots:

  1. Header: the token type and signing algorithm, such as {"alg":"HS256","typ":"JWT"}.
  2. Payload: the claims, such as the user ID (sub), roles and expiry time (exp).
  3. Signature: a hash of the header and payload made with a secret or private key.

The header and payload are Base64URL-encoded JSON, which is why this tool can decode them without any key.

Common registered claims

ClaimMeaning
issIssuer: who created the token
subSubject: usually the user ID
audAudience: who the token is meant for
expExpiration time (Unix timestamp)
nbfNot valid before (Unix timestamp)
iatIssued at (Unix timestamp)
jtiUnique token ID

Need to read a timestamp on its own? Use the Unix timestamp converter.

Frequently asked questions

Is it safe to paste a real token here?

Yes. The token is decoded entirely in your browser and is never sent anywhere. Still, treat live tokens like passwords: anyone who has one can use it until it expires.

Is a JWT encrypted?

Usually not. A standard JWT (JWS) is only signed: the header and payload are Base64URL-encoded, so anyone can read them. The signature proves the token wasn't changed, but it doesn't hide the contents. Never put secrets in a JWT payload.

What do exp, iat and nbf mean?

They're Unix timestamps. exp is when the token expires, iat is when it was issued, and nbf (not before) is when it becomes valid. The decoder shows each as a readable date and tells you whether the token is currently valid.

Can I verify the signature?

For HS256, HS384 and HS512 tokens, enter the shared secret and the decoder checks the signature using your browser's Web Crypto API. Tokens signed with RS256 or ES256 need the issuer's public key and are decoded but not verified here.