For DevOps, SRE and backend engineers debugging auth issues between services, gateways and identity providers. Paste a token and see its decoded header and payload, plus whether it has already expired.
Build industry projects on ByteLabs and add verified proof of your skills to your public profile.
You enter
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkNhcmVlckJ5dGVDb2RlIiwiaWF0IjoxNTE2MjM5MDIyfQ.<signature>
The tool shows
Header: {"alg": "HS256", "typ": "JWT"} Payload: {"sub": "1234567890", "name": "CareerByteCode", "iat": 1516239022}
No. It only Base64URL-decodes the header and payload; the signature is not checked. A token that decodes cleanly can still be forged or tampered with, so always verify it on the server.
If the payload has an exp claim, the status line converts it to a date and says either expires at that time or EXPIRED, compared with your device clock.
A JWT needs at least two dot-separated parts. Check that you copied the whole token and did not include the word Bearer or surrounding quotes.
Yes. It is free, needs no sign-up and runs entirely in your browser, so what you type is not uploaded. You only sign in if you want to email a result to yourself or save it to your CareerByteCode profile.