JWT decoder — view a token's header, payload, and expiration

When debugging a login issue, instantly check what permissions a token holds and when it expires. Decoding happens entirely in your browser.

The file is never sent to a server — processed entirely in this browser

🔒 The token is decoded only in this browser and is never sent anywhere. Since the signature isn't verified, Being able to see the content doesn't mean the token is genuine or valid.

Advertisement

How to use Decode JWT

  1. 1Paste a JWT (a leading Bearer prefix is fine too).
  2. 2The header and payload are decoded as JSON, with time values shown in KST.
  3. 3Checks whether it's expired or not yet valid. The signature is not verified.

Frequently asked questions

Is the signature verified too?

No. Only the content is decoded, without a secret or public key. Being able to decode it doesn't mean the token is valid.

Is it safe to paste a real production token?

This page never sends your token to a server. That said, clear a production token right after checking it, and revoke it if you suspect it's been exposed.

Advertisement