🔑

JWT Decoder

Parse tokens, check expiry

⚠ This tool only decodes and does not verify the signature. All processing stays in your browser and the token is never sent to a server. Still, avoid pasting real production tokens if possible.
JWT Token

How to use

Splits a JWT string into its header, payload and signature, and judges whether it has expired based on the `exp` claim. It only decodes the token; it does not verify the signature (no secret key check).

Q. Does it verify the signature too?

A. No. This tool only decodes the token so you can read the payload; it does not verify the signature with a secret key.

Q. Is my token sent to a server?

A. No. The token is parsed only inside your browser, so you can inspect sensitive tokens safely.