JWT Decoder
Decode JSON Web Tokens, check their times and, optionally, their signature with your own key, offline.
About this tool
Paste a JSON Web Token to read its header and claims. Expiry (exp), not-before (nbf) and issued-at (iat) times are shown in your time zone and in UTC, and checked against your clock, with warnings for times written in milliseconds or tokens that aren’t signed at all.
Decoding a token proves nothing about it: anyone can make one that decodes the same way. To check the signature, paste the shared secret for HS256, HS384 and HS512, or a public key, certificate, JWK or key set for RS, PS, ES and EdDSA tokens. Checking happens in your browser with the Web Crypto API.
Tokens and keys stay on this page. They aren’t saved, put in the address bar or sent anywhere, and keys referenced by the token (jku, x5u) are never downloaded.
Why does it say “not verified” for a token my app accepts?
Because nothing has checked it here yet. Your app checks signatures with its key; paste that key (public keys are safe to share) to check it on this page too.