JWT Decoder
Ek JWT ka header aur payload decode karein aur exp/iat inspect karein (bina verification ke).
Tokens aapke browser mein locally decode hote hain aur kuch bhi upload nahi hota, lekin kisi bhi online tool mein real production tokens ya secrets paste karne se bachein.
Token banakar sign karna hai? JWT Signer try karein.
JWT Decoder ke baare mein
Yeh jwt decoder kisi bhi JSON Web Token ko uske header, payload aur signature segments mein todta hai aur unhe saaf, padhne-laayak JSON ki tarah dikhata hai. Token paste karein ("Bearer " prefix ke saath ya bina) aur yeh base64url segments ko turant decode kar deta hai, phir standard time claims — exp, iat aur nbf — ko human-readable UTC dates ke roop mein dikhata hai, saath hi badges batate hain ki token expired hai, active hai ya abhi valid nahi hua. Yeh backend developers, API engineers aur QA testers ke liye banaya gaya hai jinhe auth headers debug karne, token contents inspect karne, ya kisi server-side library ke bina expiry confirm karne ki zaroorat hoti hai. Local debugging ke dauraan ise ek quick jwt parser ya token decoder online ki tarah istemaal karein. Decoding aapke browser mein locally hoti hai, isliye jo token aap paste karte hain woh kabhi aapke device se bahar nahi jaata aur kuch bhi upload nahi hota.
Features
- JWT header aur payload ko pretty-printed, syntax-highlighted JSON mein decode karta hai
- exp, iat aur nbf claims ko parse karke padhne-laayak UTC timestamps mein dikhata hai
- Tokens ko Expired, Valid, Active ya Not yet valid ke roop mein colored badges ke saath flag karta hai
- Bearer prefix ke saath ya bina tokens accept karta hai
- Raw signature segment ko alag se inspection ke liye dikhata hai
- Saaf taur par warn karta hai ki decoding kabhi token ki signature ya authenticity verify nahi karti
- Decoded header aur payload JSON ke liye Copy buttons, plus ek Clear control
JWT Decoder kaise use karein
- Apna JWT, JSON Web Token input box mein paste karein.
- Formatted JSON ke roop mein dikhaye gaye decoded header aur payload ko padhein.
- Claims section mein issued, not-before aur expiry dates aur status badges check karein.
- Header ya payload JSON lene ke liye Copy buttons istemaal karein, ya naye sire se shuru karne ke liye Clear karein.
Example
Input
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0IiwibmFtZSI6IkphbmUiLCJpYXQiOjE1MTYyMzkwMjJ9.signature
Output
Header:
{
"alg": "HS256",
"typ": "JWT"
}
Payload:
{
"sub": "1234",
"name": "Jane",
"iat": 1516239022
}
Decoder token ko todta hai aur header aur payload ko JSON ke roop mein dikhata hai; iat ek padhne-laayak date ki tarah dikhta hai.
Common errors aur troubleshooting
- Aapko error dikhta hai ki token mein kam se kam do dot-separated segments hone chahiye. — Ek JWT header.payload.signature hona chahiye. Confirm karein ki aapne poora token copy kiya hai aur dots strip nahi hue.
- Decoder bataata hai ki koi segment valid base64url ya valid JSON nahi hai. — Pakka karein ki transit mein koi characters drop ya URL-encoded nahi hue, aur aapne token khud paste kiya hai na ki uske aas-paas ka object ya quotes.
- Aapko verification ki ummeed thi par tool kehta hai ki signature check nahi hoti. — Yeh ek decoder hai, validator nahi. Yeh sirf token contents padhta hai; authenticity confirm karne ke liye signing ya verification library istemaal karein.
- Token Expired dikhta hai jabki woh recent lagta hai. — exp claim UTC seconds mein hota hai aur current time se compare kiya jaata hai. Dikhayi gayi UTC date ko apne local clock aur timezone se check karein.
Aksar pooche jaane wale sawaal
- JWT decoder kya hai aur yeh kya dikhata hai?
- Ek JWT decoder JSON Web Token ko padhta hai aur uske contents reveal karta hai. Yeh decoder poora header aur payload pretty-print karta hai aur standard time claims exp, iat aur nbf ko padhne-laayak UTC dates ke roop mein status badges ke saath highlight karta hai.
- Bearer prefix wale JWT ko kaise decode karun?
- Bas poori Authorization header value paste kar dein. JWT Decoder decode karne se pehle leading 'Bearer ' prefix automatically hata deta hai, isliye aapko ise pehle trim karne ki zaroorat nahi.
- Kya JWT Decoder token signature verify karta hai?
- Nahi. Yeh sirf header, payload aur claims decode karke dikhata hai. Yeh kabhi signature verify nahi karta, isliye sirf decoding se kabhi yeh saabit nahi hota ki token authentic hai.
- JWT Decoder mein mera token Not yet valid kyun dikhta hai?
- Iska nbf (not before) claim ka time abhi bhi future mein hai, isliye token abhi active nahi hua. Woh time guzar jaane par badge update ho jaata hai.
- Kya JWT Decoder istemaal karte waqt mera token kahin bheja jaata hai?
- Nahi. JWT Decoder poori tarah aapke browser mein chalta hai aur jo token aap paste karte hain woh kabhi aapke device se bahar nahi jaata, aur kuch bhi server par upload nahi hota.
Related tools
- JWT Signer — Ek payload aur secret se JWT (HS256/384/512) banayein aur sign karein — Web Crypto.
- Base64 Encode / Decode — UTF-8 safe Base64 encoding aur decoding.
- Hash Generator — Web Crypto API ke through SHA-256 / SHA-1 / SHA-384 / SHA-512.
- TOTP / 2FA Generator — Ek base32 secret se time-based one-time passwords (2FA codes) generate karein.
- Password Generator — Strength meter ke saath strong, random passwords generate karein (crypto-secure).
- Unix Timestamp Converter — Unix timestamps aur readable dates (local aur UTC) ke beech convert karein.
- URL Parser — Ek URL ko uske parts mein todein aur query parameters list karein.
- JSON Formatter — JSON ko beautify, minify aur validate karein, error ki location ke saath.
Saare ArrayKit tools