JWT decoder
Paste a JWT to see its header and payload, with exp, iat and nbf shown as readable dates and a clear expired or valid status. Signatures are only checked if you enter the secret or public key.
- ๐ Runs on your device
- โค 0 bytes uploaded
- ๐ด Works offline
- โ Free, no sign-up, no watermark
How to use JWT Decoder
- Paste the token (a leading "Bearer " is fine).
- Read the header, payload and claim dates.
- To check the signature, enter the secret (HS256/384/512) or public key (RS, PS, ES).
Is it private?
Yes. JWT Decoder runs entirely in your web browser. What you type is never sent to Nolo or anyone else, and the page cannot send it anywhere: its security policy only allows it to talk to nolotools.com, which has no place to receive data. Nothing is stored either: close the page and it is gone. How Nolo works.
Questions and answers
Is it safe to paste a real token here?
Yes. The token is decoded in your browser and never sent anywhere; the page cannot contact any other site. Still, treat live tokens like passwords and prefer expired or test tokens when you can.
Does decoding verify the token?
No. Anyone can decode a JWT because the header and payload are only Base64url-encoded. The signature is checked only when you enter the secret or public key, using your browser's WebCrypto.
Which algorithms can it verify?
HS256, HS384 and HS512 with a shared secret (text or Base64), and RS256/384/512, PS256/384/512 and ES256/384/512 with a public key as PEM (BEGIN PUBLIC KEY) or JWK.
How is expiry shown?
exp, iat, nbf and auth_time are Unix timestamps in seconds. They are shown in your local time, in UTC and relative to now, with a status such as "Expired 3 hours ago".
Can it decode encrypted tokens (JWE)?
No. A JWE has five parts and its payload is encrypted, so only the header can be read without the key. The tool tells you when a token is a JWE.