Developer
JWT Decoder
Paste a JSON Web Token to see its header, payload and standard claims, with expiry times as real dates. Decoding happens on your device.
Paste a JWT or a whole Bearer …value. It's decoded in your browser and never stored or sent.
Instant decoding
Header and payload appear as formatted JSON as soon as you paste — including Urdu and emoji text.
Expiry at a glance
exp, iat and nbf shown as dates in your time zone, with “expires in 2 hours” style countdowns.
Private
Tokens are decoded locally and never stored or sent — but treat live tokens like passwords anyway.
What is a JWT?
A JSON Web Token (JWT) is a compact, URL-safe way to pass claims — like a user ID and role — between a login server and an API. It has three base64url parts separated by dots: header.payload.signature.
- Header: the signing algorithm (
alg, e.g. HS256 or RS256) and token type. - Payload: the claims. Anyone can read them, so never put secrets in a JWT.
- Signature:proves the token was issued by someone holding the key and hasn't been changed.
Standard claims
iss— issuer: who created the tokensub— subject: usually the user IDaud— audience: which API the token is meant forexp— expiry time, in seconds since 1 January 1970 (UTC)nbf— not valid before this timeiat— when the token was issuedjti— a unique ID for the token
Decoding is not verifying
This decoder doesn't check the signature. Anyone can make a token that says "role": "admin", so your backend must always verify the signature (and exp, aud and iss) with a proper library before trusting a token.
Security tips
- Live tokens work like passwords — don't paste them into tools you don't trust or share them in chats.
- Keep access tokens short-lived (minutes, not days) and refresh them.
- Reject tokens with
alg: none, and don't let the token choose which algorithm your server accepts.
Private by design. Everything runs in your browser — nothing you enter is uploaded or stored by AISeekho.