Secrets and encoding

How to decode a JWT header and payload

You have a bearer token and need the claims. Decode it on JWT Decoder.

A JWT decode shows header and payload JSON. The signature is not checked, and exp is seconds.
A decode shows header and payload JSON, and the signature is not checked.

What to run

Open JWT Decoder. It stays in the browser.

How to read the result

Header names the algorithm.

Payload is JSON claims.

The signature is not checked.

Anyone can forge a payload that decodes. Treat it as a label, not a proof.

What to open next

Open JSON Formatter if you want the payload pretty-printed. It stays in the browser.

Open Unix Timestamp Converter on exp, nbf, and iat. It stays in the browser.