JWT Decoder
Reads the header and payload of a JSON Web Token. It does not check the signature.
0 characters
A JWT has three parts separated by dots (header.payload.signature).
What is JWT Decoder?
A JSON Web Token (JWT) is a compact string used to send information between systems, most often to prove who a user is after they sign in. It has three parts separated by dots: a header, a payload and a signature.
The header and payload are only encoded, not encrypted, so anyone holding the token can read them.
What this tool does
Decodes the header and the payload of a token into readable JSON, and converts the dates in the payload, such as iat and exp, into readable times. It does not check the signature, so it cannot tell you whether a token is genuine.
How to use it
- Paste the token. A leading "Bearer " is fine.
- Leave Auto ticked, or press Decode JWT.
- Read the header, the payload and the dates.
Did you know?
- JWTs are defined in RFC 7519.
- Because the payload can be read by anyone, never put passwords or other secrets in a token.