Start Project

© 2026 Gopafy · All rights reserved

Developer ✓ Free Forever ✓ Works Offline

JWT Decoder

Paste a JSON Web Token to decode the header, payload and inspect expiry claims — all in your browser.

. .
Header Payload Signature

Token is EXPIRED
Token is valid (not expired)

Header


                

Payload



                    
                    
Dominate Google. Bring in more customers.
Gopafy Partner

Dominate Google. Bring in more customers.

Technical SEO, local SEO & content strategy — built for Indian businesses.

Websites App Development Social Media Marketing SEO

Frequently Asked Questions

What is a JWT?

A JSON Web Token (JWT) is a compact, URL-safe way to represent claims between two parties. It consists of three Base64URL-encoded parts separated by dots: header, payload, and signature.

Can this tool verify the JWT signature?

This tool decodes and displays the header and payload without signature verification — that requires the secret or public key. For security, never share your signing secrets in a browser tool.

Is it safe to paste my JWT here?

All decoding happens entirely in your browser — nothing is sent to any server. However, avoid pasting production tokens with sensitive user data in any online tool as a best practice.

What claims are in a JWT payload?

Common claims include: iss (issuer), sub (subject/user ID), aud (audience), exp (expiry timestamp), iat (issued at), nbf (not before), and custom application-specific claims.

What is the exp claim in JWT?

The exp claim is a Unix timestamp representing when the token expires. This tool converts it to a human-readable date and tells you if the token is already expired.

Is this tool free?

Yes. Gopafy's JWT Decoder is 100% free. All processing runs in your browser.

100% Free
Always & forever
No Login
No signup needed
1,000+ Helped
Growing daily
4.9 / 5 Rating

Love this tool? Rate us

Partner

Rank higher. Get more customers.

SEO & digital strategy to dominate Google and grow your business.