JWT Decoder
Decode the Base64URL header and payload of a three-part JWS JWT and display common time claims readably.
How to use
- Paste a JWT and run to inspect the JOSE header, claims, and localized iat, nbf, or exp times.
Capabilities and scope
A dedicated runner requires header.payload.signature, shows the signature segment, but performs no cryptographic signature verification.
How it works
Base64URL characters are normalized, padding is restored, bytes are decoded as UTF-8, and header/payload JSON is parsed.
Example
A token containing an HS256 header and an exp claim displays both JSON objects plus the localized expiry time.
Useful for
- Debug JWT contents or inspect claim values
Before you use it
- Decoded content is untrusted until the token signature and claims are verified by the application.
Standards and references
Frequently asked questions
Does this verify that the signature is valid?
No. It explicitly decodes only and does not perform signature verification.