JWT Inspector
Decode a JWT header and payload, inspect claims and check expiry. Decoding does not verify the signature.
Encoded token
How to use the JWT Inspector
- Paste a JSON Web Token, with or without the
Bearerprefix, or click Sample. - See the header, the payload and every claim explained, with dates in readable form.
- The status shows whether the token has expired, isn't valid yet, or never expires.
Decoding is not verifying
A JWT's header and payload are only Base64url-encoded, so anyone can read them, and anyone can create a token with any contents. What makes a token trustworthy is its signature, checked by your server with the right secret or public key. This tool decodes tokens but doesn't verify signatures. Never trust a token just because it decodes.
What the parts mean
- Header: the signing algorithm (
alg, e.g. HS256 or RS256), the token type and often a key ID (kid). - Payload: the claims, such as who the token is about (
sub), who issued it (iss), who it's for (aud) and when it expires (exp). - Signature: proves the header and payload weren't changed, if it verifies.
Frequently asked questions
Is it safe to paste a real token here?
The token is decoded entirely in your browser and never sent anywhere. Still, a valid token is a credential: avoid pasting live production tokens into any website, and prefer expired or test tokens.
Why does it say "No expiry"?
The token has no exp claim, so it stays valid until the signing key changes. Tokens should normally be short-lived.
What is alg "none"?
An unsigned token. Accepting these is a well-known vulnerability: an attacker can change any claim. Servers should reject them.
What about encrypted tokens (JWE)?
Tokens with five parts are encrypted. Their payload can only be read with the recipient's private key, so they can't be decoded here.
Related tools
All tools- Base64 Encoder / DecoderEncode text to Base64 and decode Base64 to text, with UTF-8 and URL-safe support.
- Unix Timestamp ConverterConvert Unix timestamps in seconds, milliseconds or nanoseconds to ISO 8601 and any time zone, and back.
- JSON FormatterFormat, validate and minify JSON with syntax highlighting and precise error locations.
- JSON ValidatorValidate JSON, see the exact line and column of syntax errors, and fix common mistakes.
- JSON MinifierRemove whitespace from JSON and see the original size, minified size and savings.