JWT Expiry Checker & Decoder
Inspect, decode, and verify JSON Web Tokens (JWT) locally inside your browser. Features live expiration countdown timers, header/payload analysis, and signature validation.
Ready to use JWT Expiry Checker & Decoder?
Runs instantly in your browser sandbox. No sign-up required.
Your tokens and secrets never leave your browser memory.
Real-time countdown timer to detect exp/nbf token expiration.
Instant Base64URL decoding with JSON syntax highlighting.
What is a JSON Web Token (JWT)?
A JSON Web Token (JWT) is an open standard (RFC 7519) that defines a compact and self-contained way for securely transmitting information between parties as a JSON object. This information can be verified and trusted because it is digitally signed. JWTs can be signed using a secret (with the HS256 algorithm) or a public/private key pair using RS256 or ES256.
How the JWT Expiry Checker Works
When you paste an encoded token into our JWT Expiry Checker, the tool parses the three dot-separated Base64URL segments:
- Header: Contains the algorithm (
alg) and token type (typ). - Payload: Contains claims (statements about an entity, usually the user, plus metadata like
exp,iat,iss, andsub). - Signature: Used to verify that the sender of the JWT is who it says it is and to ensure that the message was not modified in transit.
Understanding Key JWT Claims
Our tool automatically extracts and evaluates standard registered claim names:
exp(Expiration Time): Identifies the expiration time on or after which the JWT MUST NOT be accepted for processing. Rendered as a human-readable countdown in our app.iat(Issued At): Identifies the time at which the JWT was issued.nbf(Not Before): Identifies the time before which the JWT MUST NOT be accepted.iss(Issuer): Identifies the principal that issued the JWT (e.g. Auth0, Okta, Firebase).sub(Subject): Identifies the principal that is the subject of the JWT.
Why Decode JWTs Client-Side?
Many online JWT decoders send your auth tokens over the network to a central backend server, which poses a severe security risk. If a third-party server logs your bearer token, an attacker could replay it to impersonate your user account.
Our JWT Expiry Checker operates 100% inside your browser using the HTML5 Web Cryptography API and standard JavaScript Base64 decoders. Your tokens never leave your local device.
Code Snippet: Checking JWT Expiry in JavaScript
Here is how you can check token expiration in your own frontend application:
function isTokenExpired(token) {
try {
const payloadBase64 = token.split('.')[1];
const decodedJson = atob(payloadBase64.replace(/-/g, '+').replace(/_/g, '/'));
const { exp } = JSON.parse(decodedJson);
if (!exp) return false;
// exp is in seconds, Date.now() is in milliseconds
return Date.now() >= exp * 1000;
} catch (err) {
return true; // Treat invalid tokens as expired
}
} Frequently Asked Questions
Is it safe to paste real JWT tokens into this decoder tool?
Yes, 100% safe. The JWT Expiry Checker executes entirely inside your browser memory sandbox using native JavaScript decoders. Your tokens are never uploaded to any backend server or logged in remote network traces.
What is the difference between decoding a JWT and verifying its signature?
Decoding converts Base64URL string segments back into readable JSON headers and payload claims. Verifying recalculates the cryptographic signature using the secret or public key to ensure data has not been modified in transit.
How does the live countdown timer calculate token expiration?
The tool extracts the "exp" (Expiration Time) claim from the payload (measured in UNIX epoch seconds), compares it to your local browser clock (Date.now()), and updates a real-time countdown every second.
Why does my JWT show as expired immediately?
JWT expiration claims are in seconds, while standard JavaScript Date objects use milliseconds. If an application fails to multiply the exp claim by 1000, or if your local system time is skewed, the token will register as expired.