Inspect the claims in your token.
Read headers, inspect claims and check token timestamps. Your token stays in your browser.
JWT Decoder & Inspector
Read JWT headers and claims, inspect timestamps, and understand the contents directly in your browser.
{"alg":"HS256",
"typ":"JWT"}{"sub":"123",
"role":"reader"}1. Paste your token
Three-part JWTs only. Encrypted JWE tokens are not supported.
2. Inspect the contents
Signature NOT verified. Decoding does not establish trust or authorize access.
Header
Paste a token to begin.
Payload
How to use it
- 1Paste the token
The whole JWT, with or without the Bearer prefix.
- 2Read the header and claims
The header and payload are decoded and laid out, with timestamps converted to readable UTC dates.
- 3Check the timing
Expiry, not-before and issued-at are compared with the current time so you can see whether the token is still in its window.
Good to know
Decoding, not verification
A JWT payload is only base64url text. This page reads it; it does not check the signature.
Timestamps in UTC
exp, nbf and iat are Unix seconds and are shown in UTC to avoid timezone confusion.
Missing claims are reported
A token with no exp is reported as having none, rather than being treated as valid forever.
Your token stays here
Nothing is uploaded, which matters because a bearer token is a live credential.
Common uses
- Checking why an API call returned 401
- Confirming which scopes or roles a token carries
- Seeing when a session token expires
- Comparing claims between two environments
- Reading the kid and alg before debugging key rotation
Questions
Does this verify the signature?
No. It decodes and displays the contents. Signature, issuer and audience must be validated by your server with the right key.
Is it safe to paste a real token here?
The decoding happens in your browser and nothing is sent anywhere. Still treat a live token as a password: prefer an expired or test token, and rotate anything you paste into any tool.
What do exp, nbf and iat mean?
exp is when the token expires, nbf the earliest time it may be accepted, and iat when it was issued. All three are Unix seconds.
Why does my token show as expired when the API accepts it?
Servers often allow a small clock skew, and your own clock may differ. Compare the exp value with the server time before concluding anything.
Understand your claims
exp is the expiry time, nbf is the earliest acceptance time, and iat is the issue time. Dates use Unix seconds and are shown in UTC. Missing timestamps are reported rather than treated as proof of validity.
Header and claim values are untrusted. Validate signatures, issuer, audience and application requirements on your server. JWT specification.