Developer Tools
Decode Base64URL JWT header and payload data, copy pretty JSON, inspect exp, iat and nbf in UTC and local time, and see expiration status without fetching keys or contacting issuers.
Simple workflow
How to use JWT Decoder
- 1Paste a three-part JWT.
- 2Decode header and payload locally, then inspect optional time claims.
- 3Copy the pretty JSON without treating the token as verified.
Good to know
Frequently asked questions
Does decoding verify the signature?
No. Decoding does not verify a signature or prove authenticity. This tool never fetches JWKS or issuer URLs.
Does the token leave the browser?
No. Token contents are not sent to UtilSprout, analytics or any third party.
How are time claims shown?
Finite numeric exp, iat and nbf values are interpreted as Unix seconds and shown in both UTC and your browser's local time.
Practical guide
Read token claims without making a trust decision
A JWT commonly stores JSON in Base64URL-encoded header and payload segments. Decoding makes those fields readable but does not verify the cryptographic signature or establish who created the token.
This tool performs no issuer lookup and never fetches JWKS. Numeric exp, iat and nbf claims are shown as Unix seconds in UTC and local time for inspection only.
Worked example
Inspect an expiration claim
- Start with
- Paste a three-part JWT with an exp field.
- Choose
- Select Decode JWT.
- You get
- Header and payload JSON appear with a readable UTC/local expiration and status.
Tips for a useful result
- Treat pasted tokens as sensitive.
- Verify signatures in the system that owns the key policy.
- A readable payload can still be forged.
Keep going