JWT decoder
Paste a JSON Web Token and read its header and payload, with the exp, iat and nbf times turned into dates and a note on whether it has expired. This page only decodes: it does not check the signature, and the token is not sent anywhere.
This tool needs JavaScript. If you still see this after a few seconds, JavaScript is switched off in your browser or the page did not load completely: turn JavaScript on or reload the page.
Decode only: the signature is not checked. This page reads what is inside a JWT, which anyone can read. It does not prove that the token is genuine or unchanged (that needs the issuer's key, which this page does not accept). The token is not sent anywhere, but to be safe do not paste a real token of a live system: use a test token or one that has expired.
How to use it
- Paste the JWT in the box (it starts with
eyJ; aBearerin front is fine). The result appears at once. - Read the Header (algorithm, type) and the Payload (the data in the token). Press "Copy" to take them.
- Read the list of standard claims: issuer (iss), subject (sub), audience (aud) and the times, shown in your own time zone with how long is left or how long ago it ended.
Frequently asked questions
Can this page check that a JWT is genuine?
No, and that is on purpose. Checking the signature needs the issuer's secret (HS256) or public key (RS256, ES256), which should not be put into a web page. So this page only decodes, which anyone can do because the data in a JWT is not encrypted. A system that receives tokens must always check the signature on the server.
Why is there a warning that alg is none?
A JWT whose alg is none has no signature, so anyone can make one. A system that trusts such tokens is easy to forge. A correct system rejects a token that does not carry the signature it expects.
What are exp, iat and nbf?
They are Unix times (the number of seconds since 1 January 1970 UTC). iat is when the token was issued, nbf is when it starts to be valid and exp is when it expires. This page turns them into readable dates, in your time zone and in UTC.
Good to know
- An encrypted token (JWE) has 5 parts and cannot be read without the key.
- Anyone can read the payload, so never put secrets such as passwords in a JWT.
- The times are compared with your computer's clock. If the clock is wrong, the expiry status is wrong too.
Your data stays on your device
Everything runs in your browser. What you type, paste or open is not sent to freesabai's servers or anyone else's, and is not kept in the browser: close the page and it is gone. The site only counts how many times this page was opened and how many times someone copied or saved a result (never what was pasted or the result, and you can switch the counting off in the footer; see the privacy policy).
Report a problem or suggest an idea
Found a bug, or want this tool to do more? Tell us on the feedback page. No sign-up.
Other developer tools
JSON and data
- JSON formatter and validatorFormat, minify and validate JSON, find the error, fold it into levels
- JSON to YAML converterTurn JSON into YAML, key order kept, nothing leaves your device
- YAML to JSON converterTurn YAML into JSON, and find the line where the YAML is wrong
- JSON to CSV converterTurn a JSON list into CSV for Excel, Thai text included
- CSV to JSON converterTurn CSV into JSON, any separator, quoted fields handled
- CSV viewerOpen a CSV file as a table, sort a column, search, no spreadsheet needed
- Text and JSON diff checkerSee what changed between two texts, side by side or unified, with word highlights
Encoding, hashes and tokens
- Base64 encode and decodeBase64 for text (Thai and UTF-8), URL-safe, and files to and from Base64
- Hash generator: MD5, SHA-256, HMACHash text or files with MD5, SHA-1, SHA-256, SHA-512 and HMAC, and verify a checksum
- JWT decoderRead the header and payload of a JWT, with times you can read (decode only, no signature check)
- URL encode and decodePercent-encode or decode a link, Thai in URLs included, and take a URL apart
- HTML entities encode and decodeTurn special characters into & < > " and back
Generators
Time, numbers and colour
- Unix timestamp converterConvert a timestamp (seconds or milliseconds) to a date and back, with time zones
- Cron expression explainerRead a cron expression in plain words and see its next 5 runs
- Number base converterConvert between binary, octal, decimal and hex, and do bitwise AND, OR, XOR and shifts
- Colour converter: HEX, RGB, HSLConvert a colour between HEX, RGB and HSL, or pick one by eye
- Colour contrast checker (WCAG)Check the contrast between text and background colours for WCAG AA and AAA
Text and code
- Regex testerTry a regular expression, see matches and groups, protected from regexes that never finish
- Markdown previewType Markdown and see it rendered at once, safely, with embedded scripts never run
- Character, word and line counterCount characters, words (Thai too), lines, sentences, paragraphs and reading time