A JWT is three Base64URL-encoded segments joined by dots. The first is the header — it tells you the algorithm (HS256, RS256, ES256, etc.) and token type. The second is the payload — where the actual claims live: sub (who this token is for), exp (expiry timestamp), iat (issued at), plus any custom claims your auth system adds. The third is the signature. This tool decodes the first two and shows them as readable JSON. It cannot verify the signature without the signing key, so treat the decoded payload as informational only — it doesn't tell you whether the token is valid, only what it claims to contain.
The expiry timestamp trips people up regularly
The exp claim is a Unix timestamp in seconds, not milliseconds. So a value like 1753660800 means a specific date — not "this many milliseconds from now." If you paste a token here and the expiry time looks wildly wrong, that's usually why: the issuing system accidentally used milliseconds instead of seconds, which puts the expiry somewhere in the year 2525. Worth checking in the payload view. Also, the nbf (not before) claim is less commonly used but works the opposite way — the token is not valid until that timestamp. You'll see it in tokens that are issued ahead of time and should only become active later. The parsed payload view here shows all claims including these, with the timestamps converted to human-readable date strings so you don't have to do the conversion manually.
