15 / 17 · DEVELOPER

JWT Decoder

Paste a JSON Web Token to read its header and claims, with the timestamps resolved and the risks flagged — expired, unsigned, no audience. Decoded on our server; the signature is never verified and no key is ever asked for.

  • Not stored by NexKit
  • 20,000 characters
  • No sign-up
01

JSON Web Token

or paste your own — anything goes

0 / 20,0000 words

02

Settings

Show as

Annotated reading, or the raw decoded JSON.

⌘↵ to run

03

Decoded token

STANDING BY

This panel has nothing to do yet.

Put some text into 01 and it lands here. The sample works too, if you would rather not think of anything.

Awaiting output

How your text is processed. Pressing Decode token sends your text to NexKit's servers, where it is parsed and answered outright. No AI model is involved and nothing is passed to any third party. NexKit does not store what you submit, and there are no accounts to link it to.

01Using JWT Decoder
  1. 01

    Paste the token

    With or without the "Bearer " prefix.

  2. 02

    Pick a view

    Annotated, which resolves the timestamps, or the raw JSON.

  3. 03

    Read the warnings

    Expired, unsigned, no audience, no expiry — each one flagged with why it matters.

What people use it for

  • Find out why an API keeps rejecting a token
  • Check what scopes a token actually carries
  • See when a token expired, in readable time
  • Spot a token signed with alg=none before it reaches production

Questions

Is my token sent anywhere?

No. A JWT is base64 and JSON, so it is decoded on our server and no AI provider is involved. That said, a token is a credential: if it is a live production token, treat pasting it anywhere as a reason to rotate it.

Does this verify the signature?

No, and deliberately so. Verifying needs the signing key, and no tool should ever ask you to paste a signing key into a web form. Everything shown is a claim the token makes, not a fact you can rely on until something with the key has checked it.

What does alg "none" mean?

It means the token is unsigned — anyone can change any claim in it without detection. It exists in the spec for tokens whose integrity is guaranteed some other way, but a verifier that accepts alg=none accepts forgeries. It is the classic JWT vulnerability, and the tool flags it as a warning.

02Next toolsAll tools →