Security & Crypto
JWT Decoder
Decode a JSON Web Token header and payload locally. The signature is not verified.
Results appear here.
What the result means
A compact JSON Web Token is three segments separated by dots. This page splits on the dots and stops unless there are exactly three parts. The first segment is the header and the second is the payload. Both are Base64url, so minus and underscore are mapped back to the standard alphabet, padding is restored, and the JSON is pretty-printed. The third segment is the signature. It is not decoded as JSON and it is not checked against any key. When the payload contains a numeric exp claim, that instant is compared with the current time and labelled expired or not expired. If the claim is missing, the page says so. None of this proves who issued the token. The token is not sent anywhere.
Related tools
Questions
Does this check the signature?
No. The signature is not verified, and the page will not ask you for a key. Header and payload are only decoded and printed, so a tampered token can still look tidy. Do not use the result to grant access or to decide that an issuer is real.
What is the exp claim?
The exp claim is the expiration time in seconds since the Unix epoch, stored in the payload. When that claim is a number, the page compares it with the current time and says expired or not expired. If exp is absent, the page says there is no exp claim. A missing claim is not proof that the token lasts forever.
Why does a token need three parts?
Compact form is a header, a payload, and a signature, separated by dots. This page requires all three segments and decodes only the first and the second as JSON. The third segment is left untouched and is not treated as evidence. A string with a different number of parts is rejected.