The token does not leave your browser. It never reaches the address bar, nothing is stored and nothing is sent anywhere — this site is made of static files and has no server to send it to. Reload the page and it is gone.

Paste a token to start.

A JWT’s dates are in SECONDS since 1970, not milliseconds: RFC 7519 says so, and anyone arriving from Date.now() gets it wrong. Multiplying by a thousand is the difference between this year and 1970.

The parts are base64url — hyphen and underscore instead of plus and slash, and no padding — and the bytes are read as UTF-8. A decoder that skips the second step shows accented names wrongly without raising any error at all.

How it works

  1. Paste the token. It does not leave your browser — it never reaches the address bar, nothing is stored, nothing is sent.
  2. Header and payload open up formatted: known fields carry their gloss beside them.
  3. Dates come out in your zone and in UTC, with the state: in date, expired, not yet in force.

Why it exists

Because nine times out of ten the question is “is this token expired?”, and answering it takes three steps nobody wants to do by hand: split the three parts, decode base64url, and work out that 1721048400 is a date and which year it falls in.

And because the alternative — pasting the token into the first decoder a search turns up — means sending a credential to a server you do not know.

About the signature, which is the most important thing on this page

The signature is not verified. That is not a missing feature to add later: verifying it means having the key, and a page that asks you for your signing key is a page to close. There is no honest way for a decoder in a browser to tell you a token is authentic.

A choice of words follows, and it is worth noticing: this tool never says “valid”. It says in date, expired, not yet in force — statements about the dates, which is everything that is known. A token can be perfectly in date and completely forged.

For the same reason there is no green. On this site green means “right” — the string in tune, the form sent — and painting a token green when nobody has checked its signature would be the same lie told with colour instead of with words.

About the dates

They are in seconds since 1970, not milliseconds. RFC 7519 says so, and anyone arriving from Date.now() gets it wrong: multiplying or not multiplying by a thousand is the difference between this year and 1970. Here they appear twice, in your zone and in UTC, because a token issued by a server on another continent is read in UTC and discussed in your own time.

A time field written as a string is refused rather than converted. It happens — it is not conformant, but it happens — and converting it would give a plausible date without saying the token is out of spec.

About base64url, which is not base64

It uses hyphen and underscore instead of plus and slash, and has no padding. A decoder that expects padding fails on almost every real token.

And then the bytes have to be read as UTF-8. That is the step most often skipped, and when it is skipped nothing visible happens: a name with an accented letter comes out wrong, and it looks like a problem with whoever issued the token.

The field here also accepts classic base64 and stray padding. A token like that is formally malformed, but this is a viewer: whoever pastes it wants to read what is inside, not receive a lecture.

About your data

The token does not leave your browser. It never reaches the address bar — a JWT in a query string ends up in history, in proxy logs and in the Referer header — nothing is stored and nothing is sent anywhere. This site is made of static files and has no server to send it to, even if it wanted one. Reload the page and it is gone.

From here you also go here

px, rem, em converter

The three units live together, with a configurable base and the typographic scale of the value on exact ratios.

Development

Subnet calculator

Network, broadcast, range and usable hosts of an IPv4 block, with the two exceptions almost no calculator explains.

Development

UUID generator

Version 4 UUIDs, one at a time or in batches, in lowercase, uppercase, without hyphens or in braces.

Development

All tools