What decoding shows you
A JWT (JSON Web Token) is three Base64url-encoded parts joined by dots: a header naming the signing algorithm, a payload of claims, and a signature. This tool decodes the header and payload back to JSON, and turns the standard time claims — exp (expiration), iat (issued at) and nbf (not valid before) — into a UTC timestamp plus a relative time like "expires in 3 hours", with an Expired badge once exp has passed.
Decoding needs no key because the header and payload are only Base64url — anyone can read them. That is why decoding a JWT never proves it is authentic. If your token uses HS256, paste the shared secret and this page checks the signature locally with the Web Crypto API; RS256/ES256 (public-key) tokens are not checked here.
Frequently asked questions
Is decoding a JWT the same as verifying it?
No. Decoding just reads the Base64url-encoded JSON in the header and payload — anyone can do this with no key. Verifying checks the signature against a secret or public key and proves the token was issued by whoever holds it and hasn’t been altered. Only trust claims from a token you have verified.
What do exp, iat and nbf mean?
They are registered claims from RFC 7519: iat is when the token was issued, exp is when it stops being valid, and nbf is the earliest time it becomes valid. All three are Unix timestamps (seconds since 1970-01-01 UTC).
Why can’t I verify my RS256 token here?
RS256 and ES256 are signed with a private key and verified with a matching public key, not a shared secret. This page focuses on the common HS256 case using Web Crypto; verify RS/ES tokens with your identity provider’s public key (JWKS) on a server.
Is my token sent anywhere?
No. Decoding and the optional HS256 check both run in your browser using the Web Crypto API — the token and secret never leave your device.
Why does my alg say "none"?
alg: none means the token is unsigned by design (rare, and a known attack vector if a server accepts it). Treat any token with alg: none or a mismatched algorithm as untrusted.