Developer Tools4 min read•October 8, 2026

How to Decode a JWT and Inspect Its Header, Claims and Expiry Locally

Learn how to paste a JSON Web Token, read its algorithm header and payload claims, and check the exp expiry without sending the token anywhere.

S
SmartToolPack Dev Desk✓ Verified
Reviewed by the GreenCode Developer Tools Editorial Desk
Last Updated: October 8, 2026
Disclaimer: Calculations and results provided by this tool are mathematical estimates for informational and educational purposes only. They do not constitute professional financial, tax, or legal advice.
Featured Utility Tool

JWT Decoder

Open JWT Decoder

Introduction

A JSON Web Token carries its header and claims as base64url text, so a login problem often comes down to reading what is inside. The JWT Decoder splits a token into its three parts, decodes the header and payload to formatted JSON, and converts the exp claim to a readable UTC date. Decoding runs entirely in the browser.

Step-by-Step Instructions

  1. Paste the full token into the Encoded JWT Token box, including both dots.
  2. Read the Header: Algorithm & Token Type panel to confirm the alg and typ values.
  3. Review the Payload: Claims & Data panel for sub, iat, roles or any custom claims.
  4. Check the Expiration Timestamp (exp) line, which shows the expiry as a UTC date string when the claim is present.
  5. Fix any format error reported in the output panel, such as a token with fewer or more than three dot-separated sections.

Key Use Cases

  • Auth debugging: Confirm which user id and scopes an API received when a request returns 403.
  • Expiry checks: See whether a token stored in local storage has already passed its exp time.
  • Integration review: Verify a third-party identity provider is issuing the claims your backend expects.

Frequently Asked Questions

Does the decoder verify the signature?

No. The tool decodes the header and payload only and shows the raw signature segment without validating it. A token that decodes cleanly can still be forged or tampered with, so always verify signatures on the server with the signing key.

Is the token transmitted to a server?

No. Decoding uses the browser's atob function after converting base64url characters, and nothing is sent over the network. It is still good practice to avoid pasting long-lived production tokens anywhere outside a controlled environment.

Why does it show an error for my token?

The token must contain exactly three dot-separated parts. A missing section, a truncated copy, or a header or payload that is not valid JSON after base64 decoding will produce an error message instead of the decoded panels. Check that the full token was copied without surrounding quotes or whitespace.