convertCASEpro

MODE

JWT Decoder

Paste a token to inspect what it claims.

INPUT
CHARS: 0WORDS: 0LINES: 0
OUTPUT
CHARS: 0WORDS: 0LINES: 0

How the JWT Decoder works

A JWT has three Base64URL parts separated by dots: a header, a payload of claims and a signature. The tool decodes the first two and prints them as formatted JSON. Standard time claims for issued at, not before and expiry are converted into readable dates with a relative note, and you see at once whether the token has expired.

The signature is not verified, because that needs the secret or the public key. Treat decoded claims as unverified information. Never paste live production tokens into tools you do not trust, and this one works entirely in your browser.

When it is useful

  • •Debugging why an API rejects a token.
  • •Checking the scopes, audience and expiry of an access token.
  • •Learning how JWTs are structured.
  • •Verifying that your auth server includes the claims you expect.

Frequently Asked Questions

Does decoding prove a token is valid?

No. Anyone can create a token with any content. Validity depends on the signature, which your server must verify with the right key.

Is a JWT encrypted?

A standard signed JWT is only encoded, not encrypted. Anyone with the token can read the claims, so never put secrets in them.

What does Bearer mean at the start?

It is the authorization scheme in the HTTP header. The tool strips that word automatically.

Related tools

[ Browse all tools ]