Skip to content
(347) 262-9435

Free tool · No sign-up

JWT Decoder

Decode a JSON Web Token into its header, payload, and signature without sending it anywhere. Shows every claim, resolves the timestamp claims to real dates, tells you whether the token has expired or is not yet valid, and flags the alg:none footgun. Signature verification against a shared secret is optional and also runs locally.

Paste a JWT (the eyJ… string). Decoding happens in your browser — the token is never sent anywhere.

Method & assumptions
  • Decoding reads the header and payload; it does not prove the token is authentic.
  • A token can be perfectly valid to decode and still be forged — only signature verification against the right key settles that.
  • Time claims (exp, nbf, iat) are seconds since 1970 UTC, shown here in UTC, your local zone, and relative to now.
  • Everything runs in your browser. The token and any secret you enter are never transmitted.

Software engineering

We write the software
behind tools like these

Anyone debugging auth and needing to know what a token actually says before trusting it.

Or call and speak to someone who does the work(347) 262-9435inquiries@jcitsystems.com
  • Free diagnostics
  • Same-day across most of the metro
  • Named technicians
  • No fix, no labour charge