Base64 Encoder / Decoder
Encodes and decodes Base64 for text and files.
Paste a JSON Web Token to read its header and payload, see when it was issued and when it expires, and verify the signature with your secret or public key.
| Claim | Value | Meaning |
|---|
eyJ.A signed JWT has three parts separated by dots: header.payload.signature. The header and payload are JSON encoded as Base64URL, which is Base64 with - and _ instead of + and /, and no padding.
header.payload with the algorithm named in the header's alg field and compares it with the third part.exp, iat, and nbf are Unix timestamps in seconds.This token is signed with HS256 and the secret utilza-demo-secret:
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkFkYSBMb3ZlbGFjZSIsImlhdCI6MTc2NzIyNTYwMCwiZXhwIjoxODkzNDU2MDAwfQ.mfJNFTnleCo-uVQHqKxK0ESsxp9RmZ1Y1gInltzAfwM
{"alg":"HS256","typ":"JWT"}{"sub":"1234567890","name":"Ada Lovelace","iat":1767225600,"exp":1893456000}iat 1767225600 is 2026-01-01 00:00:00 UTC, and exp 1893456000 is 2030-01-01 00:00:00 UTC.utilza-demo-secret gives Signature verified. Any other secret gives Invalid signature.| Claim | Name | Meaning |
|---|---|---|
iss | Issuer | Who created and signed the token |
sub | Subject | Who the token is about, usually a user ID |
aud | Audience | Which service the token is meant for |
exp | Expiration time | After this moment the token must be rejected |
nbf | Not before | Before this moment the token must be rejected |
iat | Issued at | When the token was created |
jti | JWT ID | A unique ID, used to stop a token being replayed |
x5c are not fetched.exp, aud, and iss.The token is decoded and verified in your browser and is never sent to a server. Even so, treat live production tokens like passwords and prefer test tokens when you can.
Yes. The header and payload are only Base64URL encoded, not encrypted. Never put passwords or other secrets in a JWT payload.
The exp claim is earlier than your device's clock. Tokens are short-lived on purpose, so get a new one from the issuer.
HS256 signs with one shared secret that both the issuer and the checker must know. RS256 signs with a private key and is checked with the matching public key, so the checker never holds the signing key.
Check whether the secret is stored as Base64. Some systems use the decoded bytes of a Base64 secret. Tick Secret is Base64 encoded and try again.
Often used together with the JWT Decoder.
Encodes and decodes Base64 for text and files.
Beautifies or minifies JSON.
Converts between Unix epoch time and readable dates, in both directions.