Paste a JWT to read its header, payload and signature. Claims like exp, iat, sub and aud are shown as readable dates. Everything is decoded locally in your browser — your token never leaves your machine.
No. A JWT's header and payload are only Base64URL-encoded, not encrypted, so anyone holding the token can read them. Verifying the signature requires the signing secret or public key, which this client-side decoder does not ask for. Watch for alg: none — it's a classic vulnerability flag.
Yes — decoding happens 100% in your browser; nothing is uploaded, logged or transmitted. Still, avoid pasting production tokens into any shared screen.
exp is the expiration time and iat the issued-at time, both as Unix timestamps in seconds. This decoder converts them to readable dates and flags a token whose exp has already passed.
JWTs are signed, not encrypted. The payload is only Base64URL-encoded, so it is readable by design — never put secrets, passwords or PII in a JWT payload.
A JSON Web Token (RFC 7519) is three Base64URL parts joined by dots: header.payload.signature. The header names the algorithm, the payload holds the claims, and the signature verifies the token hasn't been tampered with.