JWT Decoder and Claims Inspector

Read the header and payload of a JWT and see its time-based claims as dates.

Inputs stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Read the token controls

Showing an example. Edit to see your own.

Paste a three-section signed JWT. The token is read in this browser and is not sent anywhere.

Processed in your browser. Your inputs stay on this device.

How to use JWT Decoder and Claims Inspector

  1. Paste a three-section token into JSON Web Token.
  2. The header and payload appear as soon as a token is pasted.
  3. Read the header and payload as JSON, and the claim table beside them.
  4. Compare the issuer, audience and expiry dates with what you expect.

Example: JWT Decoder and Claims Inspector

Read the header and claims of a token without verifying it.

You add
A synthetic HS256 token whose payload is {"sub":"1234567890","name":"Ada Lovelace","exp":1767225600}.
You get
The header and payload appear as readable JSON, including "name": "Ada Lovelace", and exp is shown as 2026-01-01 00:00:00 UTC. The summary says Signature not verified, and the signature row states that the signature has not been checked.

Options

JSON Web Token
Paste a signed three-section token. Whitespace is ignored, so a token copied across two lines still reads. The decoder reads the token in this browser and makes no network request of its own.

Supported inputs and limits

One token up to 20,000 characters. Only three-section JWTs are read. A five-section value is refused as an encrypted token, which this page cannot decrypt, and any other count is reported with the number found. Each section must be base64url, and the first two must decode to a JSON object. The signature is shown as present or absent, with an approximate size when present, and it is never checked, because no key is collected. Expiry is compared with your device clock, which may differ from the server's. Tokens are not stored or logged.

Where your input is processed

This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

The claims worth reading first

The registered claims tell you who issued the token, who it is for and when it stops being valid. iss names the issuer, aud names the service the token is meant for, exp is the expiry as a Unix timestamp in seconds, nbf is the time it becomes valid, iat is when it was issued, and jti identifies the token itself. A scope claim carries permissions, and the server still has to enforce them.

RFC 7519, JSON Web Token

Questions about JWT Decoder and Claims Inspector

Does this tool verify the signature?

No. Checking a signature needs the issuer's key, and this page never asks for one. The output says the signature is unverified and shows an approximate size when that section is not empty.

Can I trust the claims I read here?

Treat them as text the token carries, not as facts. The header and payload need no key to write, so anyone can build a payload with a tidy issuer and a future expiry. Only a party holding the issuer's key and applying the issuer's rules can confirm a token.

Why does it say the token is expired?

The exp claim is compared with your device clock, so a wrong clock gives a wrong verdict. A token can also look current and still be refused for an audience mismatch or a revocation.

Why was my token refused?

Five sections means an encrypted token, which is not read here. Any other count means a copy problem, and the first two sections must each be base64url text that decodes to a JSON object.

Project manager: Tony Hines · Content updated 29 September 2026 · Report a problem