JWT Decoder
Decode JSON Web Tokens to read the header and payload, check expiry, and verify HMAC signatures.
100% Client-SidePaste a JWT to see its header, payload and timing claims; add the secret to verify an HMAC signature.
How to use the JWT Decoder
- 1
Paste a JSON Web Token (the three dot-separated parts) into the token box.
- 2
Read the decoded header and payload, formatted as JSON.
- 3
Check the timing claims — issued at, not before and expires — shown as readable dates with a valid/expired status.
- 4
For HS256, HS384 or HS512 tokens, enter the shared secret to verify the signature.
Frequently asked questions
More developer tools
JSON Formatter & Validator
Pretty-print, minify and validate JSON with exact error locations, sorted keys and custom indentation.
Base64 Encode & Decode
Encode text or files to Base64 and decode Base64 back to text or a file. UTF-8 safe, with URL-safe mode.
UUID Generator
Generate random v4 or time-ordered v7 UUIDs in bulk, and inspect any UUID's version and timestamp.
Missing a feature or tool?
Tell us what would make JWT Decoder more useful, or what to build next.