eyJ… → { }
JWT decoder
Paste a JSON Web Token to read its header and payload as formatted JSON. Expiry (exp), issued-at (iat) and not-before (nbf) claims are shown as dates, and Toola tells you whether the token has expired. Tokens are decoded in your browser and never sent anywhere — safe for access tokens from your own apps.
Private: your files never leave your device.
How to use JWT decoder
Step 1: Paste the token (a leading “Bearer ” is ignored).
Step 2: Read the header and payload.
Step 3: Check the dates and copy what you need.
Frequently asked questions
Does this verify the signature?
No. It only decodes the token. Verifying needs the secret or public key and should happen on your server.
Is it safe to paste a real token?
The token stays in your browser. Still, treat live tokens like passwords and don’t paste them into tools you don’t trust.
What are exp, iat and nbf?
Standard claims in seconds since 1970: expiry time, issued-at time and “not valid before” time.