JWT Decoder Widget
Embed a JWT decoder in your authentication docs. Readers paste a token and see its header and payload as formatted JSON, the issue and expiry times as real dates, and whether it has expired - with a clear note that the signature is not checked.
Live preview
Exactly what your visitors will seeUnder the widget on your page: Powered by A2Z Tools
Embed code
<iframe src="https://a2z.tools/embed/w/jwt-decoder" title="JWT Decoder by A2Z Tools" width="100%" height="810" style="border:0;width:100%" loading="lazy" allow="clipboard-write"></iframe>
A plain iframe. Works everywhere, including site builders that strip scripts. Adjust height if your content needs more room.
<div data-a2z-widget="jwt-decoder" data-height="810"></div> <script async src="https://a2z.tools/embed.js"></script>
Adds a small script (what it does) that sizes the widget to fit its content, loads it lazily and keeps it isolated from your page's CSS.
Works with
How it works
A JWT in compact form is three base64url segments separated by dots: header, payload and signature. The widget decodes the first two as UTF-8 JSON and pretty-prints them. The registered time claims exp, nbf and iat are NumericDate values - seconds since 1970 - so it shows each as a UTC timestamp, in local time and relative to now, and labels the token expired, not yet valid or not expired according to the visitor's clock. It deliberately does not verify the signature: that needs the issuer's secret or public key and must happen on your server. Encrypted tokens (JWE, five segments) are recognised and explained rather than mis-decoded. A "Bearer " prefix is removed automatically.
Method
- Token = base64url(header) . base64url(payload) . signature (RFC 7519, RFC 7515)
- exp, nbf, iat = seconds since 1970-01-01T00:00:00Z (NumericDate)
- Expired when exp <= now; not yet valid when nbf > now (device clock)
- Signature: not verified - requires the issuer's key
Limitations
- No signature verification of any algorithm (HS256, RS256, ES256, EdDSA): it cannot say whether a token is genuine or tampered with.
- Encrypted JWE tokens (five segments) cannot be read without the recipient's key; the widget identifies them and stops.
- Expiry is judged by the visitor's device clock with no leeway, so a token within a server's clock-skew allowance may show as expired here.
- JWS JSON serialisation (the non-compact form with a signatures array) is not accepted.
Where publishers use it
- OAuth 2.0 and OpenID Connect tutorials that show what is inside an ID token
- API documentation explaining access-token lifetimes and claims
- Support runbooks for diagnosing "token expired" errors
- Security training that demonstrates why a JWT payload is readable by anyone
Questions
Does this check that the token is genuine?
No. Decoding only reads the contents. Anyone can create a token with any payload; only verifying the signature with the issuer's key proves it is genuine.
Is it safe to paste a real token?
The widget never sends it anywhere, but a valid token works like a password until it expires, so avoid pasting production tokens where others can see your screen.
Why is the expiry status different from my server?
It uses the visitor's device clock. Servers also allow some clock-skew leeway, typically a minute or two.
What does alg "none" mean?
The token is unsigned. Servers must reject such tokens; the widget highlights it.
Sources
- RFC 7519: JSON Web Token (JWT) - IETF . Registered claims; exp (4.1.4), nbf (4.1.5), iat (4.1.6); NumericDate definition
- RFC 7515: JSON Web Signature (JWS) - IETF . Compact serialisation: three base64url segments
- RFC 7516: JSON Web Encryption (JWE) - IETF . Five-segment encrypted tokens, recognised but not decrypted
Cite or recommend this tool
If you reference this tool in an article, course or documentation, these formats are ready to copy. They are optional - nothing is added to your site unless you paste it.
A2Z Tools JWT Decoder https://a2z.tools/jwt-decoder
<a href="https://a2z.tools/jwt-decoder">A2Z Tools JWT Decoder</a>
[A2Z Tools JWT Decoder](https://a2z.tools/jwt-decoder)
JWT Decoder by A2Z Tools - https://a2z.tools/jwt-decoder
Related widgets
-
Encode text to Base64 or decode it, with proper UTF-8 and an optional URL-safe alphabet.
-
Pretty-print, minify or validate JSON, with the line and column of the first syntax error.
-
Live epoch time, timestamp to date (seconds to nanoseconds detected) and date to timestamp.
-
MD5, SHA-1, SHA-256, SHA-384 and SHA-512 of any text, in hex or Base64.
-
Convert a JSON array of objects to CSV and CSV back to JSON, with RFC 4180 quoting.
-
Percent-encode or decode text and URLs, and find the exact position of a malformed escape.