🔑
JWT Decoder
Parse tokens, check expiry
⚠ This tool only decodes and does not verify the signature. All processing stays in your browser and the token is never sent to a server. Still, avoid pasting real production tokens if possible.
JWT Token
How to use
Splits a JWT string into its header, payload and signature, and judges whether it has expired based on the `exp` claim. It only decodes the token; it does not verify the signature (no secret key check).
Q. Does it verify the signature too?
A. No. This tool only decodes the token so you can read the payload; it does not verify the signature with a secret key.
Q. Is my token sent to a server?
A. No. The token is parsed only inside your browser, so you can inspect sensitive tokens safely.