freesabai

Developer tools

JWT decoder

Paste a JSON Web Token and read its header and payload, with the exp, iat and nbf times turned into dates and a note on whether it has expired. This page only decodes: it does not check the signature, and the token is not sent anywhere.

This tool needs JavaScript. If you still see this after a few seconds, JavaScript is switched off in your browser or the page did not load completely: turn JavaScript on or reload the page.

How to use it

  1. Paste the JWT in the box (it starts with eyJ; a Bearer in front is fine). The result appears at once.
  2. Read the Header (algorithm, type) and the Payload (the data in the token). Press "Copy" to take them.
  3. Read the list of standard claims: issuer (iss), subject (sub), audience (aud) and the times, shown in your own time zone with how long is left or how long ago it ended.

Frequently asked questions

Can this page check that a JWT is genuine?

No, and that is on purpose. Checking the signature needs the issuer's secret (HS256) or public key (RS256, ES256), which should not be put into a web page. So this page only decodes, which anyone can do because the data in a JWT is not encrypted. A system that receives tokens must always check the signature on the server.

Why is there a warning that alg is none?

A JWT whose alg is none has no signature, so anyone can make one. A system that trusts such tokens is easy to forge. A correct system rejects a token that does not carry the signature it expects.

What are exp, iat and nbf?

They are Unix times (the number of seconds since 1 January 1970 UTC). iat is when the token was issued, nbf is when it starts to be valid and exp is when it expires. This page turns them into readable dates, in your time zone and in UTC.

Good to know

Your data stays on your device

Everything runs in your browser. What you type, paste or open is not sent to freesabai's servers or anyone else's, and is not kept in the browser: close the page and it is gone. The site only counts how many times this page was opened and how many times someone copied or saved a result (never what was pasted or the result, and you can switch the counting off in the footer; see the privacy policy).

Report a problem or suggest an idea

Found a bug, or want this tool to do more? Tell us on the feedback page. No sign-up.

Other developer tools

JSON and data

Encoding, hashes and tokens

Generators

Time, numbers and colour

Text and code