🔑 JWT Decoder
Decode and inspect JWT tokens instantly — view header, payload, and signature. Verify signatures with your secret. Free online JWT decoder — nothing sent to any server.
How to Use
1
Paste your JWT
Copy your JWT token (starting with eyJ) and paste it into the input field.
2
Click Decode
Press Decode to instantly split and decode all three parts: header, payload, and signature.
3
Inspect the token
Read the decoded JSON, check expiration dates, algorithm, and any custom claims in the payload.
Frequently Asked Questions
What is a JWT?
A JSON Web Token (JWT) is a compact, URL-safe token used for authentication and information exchange. It consists of three Base64URL-encoded parts separated by dots: Header.Payload.Signature.
Is it safe to paste my JWT here?
Yes. This tool runs 100% in your browser — your token is never sent to any server. However, never share JWTs containing sensitive data in public forums or untrusted tools.
Can this tool verify the JWT signature?
No. Signature verification requires the secret key or public key used to sign the token, which only your server knows. This tool decodes and displays the token contents only.
What does "exp" mean in the payload?
"exp" is the expiration time as a Unix timestamp (seconds since Jan 1, 1970). This tool automatically converts it to a human-readable date and shows whether the token has expired.
What is the difference between "iat" and "nbf"?
"iat" (issued at) is when the token was created. "nbf" (not before) is the earliest time the token is valid. Both are Unix timestamps.
完整指南:JWT解码器
什么是JWT?
JWT(JSON Web Token)由三个Base64URL编码的部分组成,以点分隔:头部.载荷.签名。载荷包含声明(claims):用户ID、角色、过期时间。载荷对任何人可见——切勿在其中包含敏感数据而不加额外加密。
如何使用
- 粘贴完整JWT到输入字段。
- 头部和载荷被解码为格式化的JSON。
- 检查过期时间(
exp字段,Unix时间戳)。 - 检查声明调试认证问题。
专业技巧
- 此工具仅用于解码——签名验证需要服务器上的密钥。
- 如果JWT包含敏感数据,切勿将生产JWT粘贴到在线工具。
- 调试认证错误时始终检查
exp和iat。