Skip to content
Expensico

JWT Decoder

Decode JSON Web Tokens to inspect the header, payload and expiry, and optionally verify HS256 signatures. Tokens never leave your browser.

Runs in your browser. Everything you enter stays on your device. Nothing is sent to a server.

How to use the JWT Decoder

  1. Paste a JWT (with or without the “Bearer ” prefix).
  2. Read the decoded header and payload, plus human-readable dates for exp, iat and nbf.
  3. Optionally verify an HMAC signature with the shared secret.

What's inside a JWT

A JSON Web Token has three Base64URL-encoded parts separated by dots:

  1. Header — the signing algorithm (alg) and token type.
  2. Payload — the claims: who the token is about (sub), who issued it (iss), when it expires (exp) and any custom data.
  3. Signature — proves the header and payload weren't changed by someone without the key.

Read more in our guide What is a JWT?

Decoding isn't verification

Anyone can decode a JWT — the payload is only encoded, not encrypted. Never put secrets in a JWT payload, and never trust a token on the server without verifying its signature with the expected algorithm and key.

Privacy

Tokens often grant access to real accounts. This decoder runs entirely in your browser; the token and any secret you enter are never transmitted or stored.

Frequently asked questions

Why does my token show as expired?

The exp claim (seconds since 1 January 1970, UTC) is earlier than your device's current time. Check that your clock is correct, too.

Can it verify RS256 tokens?

Not currently. RS256 and ES256 need the issuer's public key (often from a JWKS URL); this tool verifies only shared-secret HMAC tokens.

Is what I enter stored or sent anywhere?

No. Calculations and processing happen in your browser. Nothing you type is sent to our servers. Some tools remember your last input in this browser's local storage for convenience; you can clear it at any time.