Skip to content

Search WPDesignVault

Try "image", "json", "schema" or "contrast". Use arrow keys to move through results.

Developer Tools

JWT Decoder

Decode a JSON Web Token in your browser to read its header and payload, with expiry and issue dates converted to readable times. Decoding is not verification: this tool never checks the signature.

Runs in your browser. Nothing you enter is uploaded. Last updated

Decoding is not verification. This tool does not check the signature. Anyone can create a token with any contents, so verify it with the issuer's key in your own code before trusting it.

How to use

  1. Paste the token (with or without the “Bearer ” prefix).
  2. Read the decoded header and payload, and the explained claims below them.
  3. Check the expiry status, then verify the signature in your own server code before trusting anything in it.

What this tool does

A JWT has three parts separated by dots: a header, a payload and a signature, each Base64URL-encoded. The header and payload are just encoded JSON, so anyone can read them. This tool decodes those two parts, explains registered claims such as exp, iat, nbf, iss, aud and sub, and shows the signature bytes as they are.

Why it matters

When an API call fails with 401 Unauthorized, the first question is usually what the token actually contains: has it expired, is the audience right, which scopes were granted? Decoding answers that in seconds.

Common uses

  • Debugging WordPress REST API or headless logins that use JWT authentication plugins.
  • Checking when an access token expires and which scopes or roles it carries.
  • Confirming the signing algorithm and key ID (kid) a provider uses.

Tips

  • Never trust a decoded payload in your application without verifying the signature with the expected key and algorithm.
  • Reject tokens whose header says “alg”: “none” unless you explicitly expect unsigned tokens.
  • Treat tokens as passwords: anyone holding a valid token can usually act as the user until it expires.

Limitations

  • This tool does not verify signatures, so it cannot tell you whether a token is genuine or has been tampered with.
  • Encrypted tokens (JWE, five parts) can only show their header; the payload needs the decryption key.
  • Expiry status uses your device clock, which may differ slightly from the server that checks the token.

Troubleshooting

  • “Not a valid JWT”: make sure you copied the whole token, with exactly two dots, and no quotes around it.
  • Strange characters in the payload: the token may be a JWE (encrypted) or a different token format, such as an opaque access token.

Frequently asked questions

Is my token sent anywhere?

No. Decoding happens entirely in your browser, and the page does not store the token. Still, avoid pasting live production tokens into any website you do not control.

Why can anyone read my JWT?

Signed JWTs are encoded, not encrypted. The signature only proves who issued them and that they were not changed. Do not put secrets in a JWT payload.

Base64 Decoder

Decode Base64 (standard or URL-safe) back to readable UTF-8 text, with clear errors for invalid input.

JSON Formatter & Beautifier

Pretty-print JSON with your choice of indentation and optional key sorting. Errors are shown with line and column.…

Unix Timestamp Converter

Convert Unix epoch timestamps to readable dates in UTC and your local time zone, or turn a date…

JSON to YAML Converter

Convert JSON to clean, readable YAML in your browser, with options for indentation and line width.

YAML to JSON Converter

Convert YAML to formatted JSON in your browser, with clear error messages that point to the line and…

Text Diff Checker

Compare two versions of any text or code side by side. Added, removed and changed lines are highlighted…

Password Generator

Create strong, random passwords in your browser. Choose the length and character types, avoid look-alike characters, and see…

UUID Generator (v4)

Generate one or up to 1,000 random v4 UUIDs at once, with uppercase, no-hyphen and brace options.