Back to tools
Encodingpublic tool

JWT Decoder

Decode a JSON Web Token into its header and payload, with readable claim dates. The signature is never verified here.

Algorithm
HS256
Segments
3
Claims
9
Signature
Not verified
Mode

Token

header.payload.signature, base64url encoded

Warning — this tool only base64url-decodes the token. It does not verify the signature, check the issuer, or confirm the audience. Never treat the output as proof the token is authentic. Algorithm note: HMAC — the same secret signs and verifies.

Header

alg, typ, kid

{
  "alg": "HS256",
  "typ": "JWT",
  "kid": "itzdabbzz-key-1"
}

Payload

Registered and private claims

{
  "iss": "https://itzdabbzz.me",
  "sub": "usr_8f21c4",
  "aud": "itzdabbzz-web",
  "name": "ItzDabbzz",
  "scope": "tools:read tools:write",
  "iat": 1768440600,
  "nbf": 1768440600,
  "exp": 1874966400,
  "jti": "b2f1c9de-4a77-4c31-9c0e-6d1f2a3b4c5d"
}

Decoded claims

9 claim(s) — time claims rendered in local time and UTC

Decoded JWT claims with human-readable labels
ClaimMeaningValueStatus
issIssuerhttps://itzdabbzz.me—
subSubjectusr_8f21c4—
audAudienceitzdabbzz-web—
nameNameItzDabbzz—
scopeScopetools:read tools:write—
iatIssued At17684406001/15/2026, 1:30:00 AM — 2026-01-15T01:30:00.000ZIssued in 20468 day(s)
nbfNot Before17684406001/15/2026, 1:30:00 AM — 2026-01-15T01:30:00.000ZNot valid until in 20468 day(s)
expExpires18749664006/1/2029, 12:00:00 AM — 2029-06-01T00:00:00.000ZValid, expires in 21701 day(s)
jtiJWT IDb2f1c9de-4a77-4c31-9c0e-6d1f2a3b4c5d—

Signature

27 base64url characters — not checked against any key

S_PUtqHSw-T1prfI2eDxorPE1eY