How to decode a JWT
- Paste the token. The whole thing, three parts separated by dots. Spaces at either end are ignored.
- Click Decode. The header and payload appear as formatted JSON on the right.
- Read the claims. If the payload has an
expclaim, an extraexpiresAtline shows it as a date and time in UTC.
Good to know
- It decodes; it doesn’t verify. The signature (the third part) is not checked, so a decoded token is not proof that it’s genuine or untampered. Your server must verify it with the right key before trusting any claim.
- Expiry is shown, not judged.
expiresAtisexpconverted from seconds to an ISO 8601 date in UTC. The tool doesn’t say whether the token has expired; compare it with the current time yourself. Other time claims such asiatandnbfare left as numbers. - Only signed tokens (JWS) with three parts. Anything else gets
A JWT has three dot-separated parts.Encrypted tokens (JWE) have five parts and can’t be read without the key. - The header and payload must be Base64URL-encoded JSON. Padding is optional and non-ASCII text such as names with accents decodes correctly. If a part isn’t valid Base64 or JSON, you see the decoder’s error message instead.
- A JWT payload is not secret. Anyone holding the token can read it, exactly as this page does. Don’t put passwords or private data in claims.
Your token stays on your device
A live JWT is a key: whoever holds it can usually act as that user until it expires. Pasting a production token into an online decoder hands it to a server you know nothing about. Here the token is split and decoded inside this browser tab and is never sent anywhere.
The page’s security policy tells your browser to block uploads, so your token can’t leave your device even by accident. You can check: open your browser’s developer tools, watch the Network tab, and decode a token. How InTheTab works
You’ll also see a few small requests to Google Analytics. That’s our visit counter, and it never receives your files. Privacy policy
Questions
Is it safe to paste a production JWT here?
Yes. The token is decoded by your own browser and never uploaded. We never get your files or text: the site has no accounts, and its only analytics, Google Analytics, counts visits without ever seeing what you add here. It’s still good practice to treat a live token like a password.
Does this verify the JWT signature?
No. It only decodes the header and payload. Verifying needs the secret or public key, and should happen on your server, not in a web page.
How do I see when a JWT expires?
Decode it and look for expiresAt at the end of the output. It’s the exp claim as a UTC date. If there’s no exp claim, there’s no expiresAt line either.
Why do I get “A JWT has three dot-separated parts”?
The text you pasted doesn’t split into exactly three parts at the dots. Check that you copied the whole token, with no part missing, and that it isn’t an encrypted token with five parts. Paste the token alone, without a Bearer prefix.