formatjson.pro
Validate, pretty-print or minify JSON in your browser — nothing is uploaded.

Decode a JWT

A JWT's middle section is just base64url-encoded JSON. Decode it, then paste the result in the tool below to pretty-print the claims. Decoding is not verifying — see the warning below.

Three parts, two of them JSON

A JWT looks like xxxxx.yyyyy.zzzzz. The first part (header) and second part (payload) are base64url-encoded JSON; the third is the signature. Base64url decode the payload and you get a JSON object of claims like sub, iat (issued-at), and exp (expiry).

Reading the timestamps

iat and exp are Unix seconds. If exp is in the past, the token is expired regardless of anything else. Multiply by 1000 to compare against JavaScript's millisecond Date.

Decoding is not verifying

Anyone can read a JWT's payload — it is not encrypted, only encoded. Never trust its contents in a backend without verifying the signature against the issuer's key. Decoding is for inspection and debugging only.

FAQ

Is a JWT encrypted?

No. The header and payload are base64url-encoded, not encrypted — anyone can read them. Confidential data should never go in a JWT payload.

Why does the base64 have no padding?

JWTs use base64url, which omits the trailing = padding and swaps + / for - _. Add the padding back before decoding with a standard base64 tool.

Can I edit a JWT's claims here?

You can read and change the decoded JSON, but re-signing requires the secret key, so an edited token will fail verification on the server.