Skip to content
NapTools

JWT decoder

Paste a JSON Web Token to see what's inside - the algorithm, the user claims, and exactly when it was issued and expires. Decoding happens in your browser, so real tokens are never sent anywhere.

How to use: JWT decoder

  1. 1Paste the token into the box. A "Bearer " prefix copied from a request header is fine.
  2. 2Read the header and payload, shown as formatted JSON.
  3. 3Check the issued (iat) and expiry (exp) times, shown in IST with "in 2 hours" style hints.
  4. 4Copy the header or payload JSON if you need it elsewhere.

What a JWT looks like

A JWT is three Base64URL-encoded parts separated by dots:

header.payload.signature

  • Header: the signing algorithm (alg, for example HS256 or RS256) and token type.
  • Payload: the claims, such as user ID (sub), roles, issuer (iss), audience (aud) and times.
  • Signature: proves the token was issued by someone holding the key and has not been changed.

Debugging common auth errors

Symptom Check
401 right after login Is exp already in the past? Server clock wrong?
Works in one service, not another Compare aud and iss claims
“Invalid algorithm” Header alg doesn’t match what the server expects

Never trust a decoded token

Anyone can create a token with any payload. Your backend must always verify the signature and the exp, iss and aud claims before trusting a JWT.

Frequently asked questions

Is it safe to paste a production token here?

The token is decoded only in your browser and never transmitted. Still, a JWT is a credential until it expires; avoid pasting live tokens into any tool you don't trust, and rotate tokens you think may have leaked.

Does this verify the signature?

No. Verification needs the secret (for HS256) or the issuer's public key (for RS256/ES256) and must happen on your server. Decoding only shows what the token claims.

Why does it say the token is encrypted?

A token with five parts is a JWE (encrypted JWT). Its contents can only be read with the decryption key.

What do iat, exp and nbf mean?

iat is when the token was issued, exp is when it expires, and nbf is the time before which it must not be accepted. All are Unix timestamps in seconds.