JWT parser
Decode a JWT locally: split header / payload / signature, Base64URL-decode and pretty-print the JSON, show standard claims with human-readable times, and check expiry — without verifying the signature.
Runs in your browserEvery computation happens in your browser — your data never leaves this device.
JWT
Paste a JWT first
What this tool does
- Debug an auth flow by pasting the JWT your API returned and reading the algorithm in the header and the claims in the payload without decoding base64 by hand.
- Tell "expired" from "not yet valid": exp / nbf / iat are shown as ISO timestamps with the remaining duration, plus an immediate expired-or-not verdict.
- Check what a third-party SSO actually sends: registered claims (iss, sub, aud, exp, nbf, iat, jti) are listed separately from custom ones so you can compare with the docs.
- Verify the signing algorithm: when header.alg is none the tool warns explicitly that the token is unsigned and anyone can forge it.
Example
Input
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
Output
header:
{
"alg": "HS256",
"typ": "JWT"
}
payload:
{
"sub": "1234567890",
"name": "John Doe",
"iat": 1516239022
}
signature: 32 bytes (not verified)
iat: 1516239022 → 2018-01-18T01:30:22.000ZThe classic jwt.io sample token. Only the signature length is reported; the signature is never verified, so a successful decode does not mean the token is trustworthy.
Frequently asked questions
Does a successful decode mean the token is valid?
No. This tool only Base64URL-decodes and pretty-prints; it never verifies the signature. Anyone can craft a token with a valid-looking header and payload and a bogus signature. Trusting a token requires the server to verify the signature with a key or public key.
Why does it say my token is valid when I am not even logged in?
The validity window only looks at exp and nbf, independent of the signature. With no exp there is no expiry verdict at all, and with an exp in the future it reports valid even if the signature is forged.
What if the token does not have three segments?
It reports that a JWT must have three segments. JWE (encrypted tokens) have five and are out of scope. If a Bearer prefix came along for the ride, it is stripped case-insensitively.
How are the time claims displayed?
exp, nbf and iat show the raw seconds, an ISO absolute timestamp, and the difference from now broken into days/hours/minutes/seconds (past values are labelled as such). Everything is computed in UTC.
Is it safe to paste a token here?
Decoding happens entirely in your browser with no network requests. That said, a token is a credential: production tokens are better handled on the server or in a dedicated tool, not on a shared machine.
Keywords:jwtjson web tokentoken令牌解析parsedecodebase64urlclaim声明exp过期