Tool guide
Inspect JWT headers and payloads
Decode the first two parts of a three-part JWT into JSON. This inspects claims without verifying signatures or token validity.
How to use
- Paste a redacted three-part JWT.
- Inspect alg in the header and claims in the payload.
- Use the time converter for exp; authentication belongs on the server.
Example and expected result
Structure: Header.Payload.Signature
Example payload: {"sub":"demo-user","exp":1704067200}
Interpret exp as a timestamp alongside application rules.Capabilities and limits
- Decoding does not prove authenticity, expiry status or access rights.
- This page does not create JWTs or decrypt JWE tokens.
Troubleshooting
Check for a Bearer prefix, missing parts and whether the first two parts contain Base64URL-encoded JSON.
Data processing and storage
Tokens are parsed in page state without automatic saving. Avoid copying production tokens into other tools or public discussions.
Read the full data-processing notice