JWT Parser

About JWT Parser

A JSON Web Token (JWT) is a compact token made of three Base64URL-encoded parts separated by dots: a header (algorithm and token type), a payload (claims such as sub, exp and iat), and a signature.

This JWT decoder shows the header and payload as formatted JSON and flags tokens whose exp claim is in the past. Decoding happens entirely in your browser, so tokens are not sent anywhere.

How to use

  1. Paste a JWT (it usually starts with eyJ).
  2. Read the decoded header and payload. An Expired badge appears when the exp time has passed.

FAQ

Does this verify the signature?

No. It only decodes the token. Anyone can decode a JWT; verifying that it has not been tampered with requires the secret or public key, and should be done on your server.

Is the JWT payload encrypted?

No. A standard (JWS) token is only Base64URL-encoded, so never put passwords or other secrets in the payload.

What do exp, iat and nbf mean?

They are Unix timestamps in seconds: exp is when the token expires, iat is when it was issued, and nbf is the time before which it must not be accepted.