JWT Decoder
Decode JWT header and payload instantly, see expiry and issued-at times in your timezone. Runs locally, so your tokens are never sent anywhere.
Decoded locally. Your token never leaves this page.
Valid until 3/17/2030, 5:46:40 PM
Header · HS256
{
"alg": "HS256",
"typ": "JWT"
}Payload
{
"sub": "1234567890",
"name": "Ada Lovelace",
"role": "admin",
"iat": 1760000000,
"exp": 1900000000
}| Claim | Value | Date |
|---|---|---|
| exp (Expires) | 1900000000 | 3/17/2030, 5:46:40 PM |
| iat (Issued at) | 1760000000 | 10/9/2025, 8:53:20 AM |
Decoding is not verification. The signature is not checked here, so never trust a token's claims without verifying it on your server.
Frequently asked questions
Is it safe to paste my token here?
Decoding happens entirely in your browser and nothing is sent or stored. Still, treat production tokens like passwords.
Does this verify the signature?
No. It only decodes. Anyone can read a JWT's contents; verification needs the secret or public key on your server.
What are exp and iat?
exp is when the token expires and iat is when it was issued, both as Unix timestamps in seconds.