JWT Decoder Widget

Embed a JWT decoder in your authentication docs. Readers paste a token and see its header and payload as formatted JSON, the issue and expiry times as real dates, and whether it has expired - with a clear note that the signature is not checked.

Developer Tools Tool Runs in your browser Free · no ads

Customize your widget

Theme
Auto follows the visitor's light/dark setting.
Style
Attribution on your page
Optional and entirely your choice. The exact line is shown in the code below; it links to the tool with rel="nofollow".
More options
Starting values
Leave blank to use the widget's defaults. Visitors can still change every value.

Live preview

Exactly what your visitors will see

Embed code

<iframe src="https://a2z.tools/embed/w/jwt-decoder" title="JWT Decoder by A2Z Tools" width="100%" height="810" style="border:0;width:100%" loading="lazy" allow="clipboard-write"></iframe>

A plain iframe. Works everywhere, including site builders that strip scripts. Adjust height if your content needs more room.

Works with

How it works

A JWT in compact form is three base64url segments separated by dots: header, payload and signature. The widget decodes the first two as UTF-8 JSON and pretty-prints them. The registered time claims exp, nbf and iat are NumericDate values - seconds since 1970 - so it shows each as a UTC timestamp, in local time and relative to now, and labels the token expired, not yet valid or not expired according to the visitor's clock. It deliberately does not verify the signature: that needs the issuer's secret or public key and must happen on your server. Encrypted tokens (JWE, five segments) are recognised and explained rather than mis-decoded. A "Bearer " prefix is removed automatically.

Method

  • Token = base64url(header) . base64url(payload) . signature (RFC 7519, RFC 7515)
  • exp, nbf, iat = seconds since 1970-01-01T00:00:00Z (NumericDate)
  • Expired when exp <= now; not yet valid when nbf > now (device clock)
  • Signature: not verified - requires the issuer's key

Limitations

  • No signature verification of any algorithm (HS256, RS256, ES256, EdDSA): it cannot say whether a token is genuine or tampered with.
  • Encrypted JWE tokens (five segments) cannot be read without the recipient's key; the widget identifies them and stops.
  • Expiry is judged by the visitor's device clock with no leeway, so a token within a server's clock-skew allowance may show as expired here.
  • JWS JSON serialisation (the non-compact form with a signatures array) is not accepted.

Where publishers use it

  • OAuth 2.0 and OpenID Connect tutorials that show what is inside an ID token
  • API documentation explaining access-token lifetimes and claims
  • Support runbooks for diagnosing "token expired" errors
  • Security training that demonstrates why a JWT payload is readable by anyone

Questions

Does this check that the token is genuine?

No. Decoding only reads the contents. Anyone can create a token with any payload; only verifying the signature with the issuer's key proves it is genuine.

Is it safe to paste a real token?

The widget never sends it anywhere, but a valid token works like a password until it expires, so avoid pasting production tokens where others can see your screen.

Why is the expiry status different from my server?

It uses the visitor's device clock. Servers also allow some clock-skew leeway, typically a minute or two.

What does alg "none" mean?

The token is unsigned. Servers must reject such tokens; the widget highlights it.

Sources

  1. RFC 7519: JSON Web Token (JWT) - IETF . Registered claims; exp (4.1.4), nbf (4.1.5), iat (4.1.6); NumericDate definition
  2. RFC 7515: JSON Web Signature (JWS) - IETF . Compact serialisation: three base64url segments
  3. RFC 7516: JSON Web Encryption (JWE) - IETF . Five-segment encrypted tokens, recognised but not decrypted

Cite or recommend this tool

If you reference this tool in an article, course or documentation, these formats are ready to copy. They are optional - nothing is added to your site unless you paste it.

A2Z Tools JWT Decoder
https://a2z.tools/jwt-decoder

Preview