How to use JWT Decoder and Claims Inspector
- Paste a three-section token into JSON Web Token.
- The header and payload appear as soon as a token is pasted.
- Read the header and payload as JSON, and the claim table beside them.
- Compare the issuer, audience and expiry dates with what you expect.
Example: JWT Decoder and Claims Inspector
Read the header and claims of a token without verifying it.
Options
- JSON Web Token
- Paste a signed three-section token. Whitespace is ignored, so a token copied across two lines still reads. The decoder reads the token in this browser and makes no network request of its own.
Supported inputs and limits
Where your input is processed
This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.
The claims worth reading first
The registered claims tell you who issued the token, who it is for and when it stops being valid. iss names the issuer, aud names the service the token is meant for, exp is the expiry as a Unix timestamp in seconds, nbf is the time it becomes valid, iat is when it was issued, and jti identifies the token itself. A scope claim carries permissions, and the server still has to enforce them.
Questions about JWT Decoder and Claims Inspector
Does this tool verify the signature?
No. Checking a signature needs the issuer's key, and this page never asks for one. The output says the signature is unverified and shows an approximate size when that section is not empty.
Can I trust the claims I read here?
Treat them as text the token carries, not as facts. The header and payload need no key to write, so anyone can build a payload with a tidy issuer and a future expiry. Only a party holding the issuer's key and applying the issuer's rules can confirm a token.
Why does it say the token is expired?
The exp claim is compared with your device clock, so a wrong clock gives a wrong verdict. A token can also look current and still be refused for an audience mismatch or a revocation.
Why was my token refused?
Five sections means an encrypted token, which is not read here. Any other count means a copy problem, and the first two sections must each be base64url text that decodes to a JSON object.