Paste a JWT and read its header and payload. Your token never leaves this computer.
Only the contents of the JWT are read. The signature is not verified, so this tool does not prove that a token is genuine.
Enter Unix seconds or milliseconds, ISO 8601, or a date like "2026-09-30 14:30".
Type text or choose a file. SHA-1, SHA-256, SHA-384 and SHA-512 are computed. The file never leaves your computer.
No. It only reads the contents. It does not prove that a token is genuine.
The token is decoded in your browser and never sent to a server. Still, avoid sharing valid tokens from live systems anywhere.
If exp is before the current time the result says expired. If nbf is in the future it says not valid yet.