Unix Timestamp Converter
Convert Unix seconds or milliseconds to readable local and UTC dates.
Open tool →Decode the header and payload of a JSON Web Token locally, inspect its timestamps, and keep the important distinction between reading a token and verifying its signature.
The sample contains alg=none, a fictional subject, and an expired timestamp. It is deliberately not a usable login token. Use Decode to inspect it, and keep the signature-not-verified warning beside the result.
| Input or check | Expected result or decision |
|---|---|
| sub: demo-user | A claim made by the sample, not proof of a user's identity. |
| exp: 0 | An expired timestamp at the Unix epoch. |
| A readable header and payload | No signature, issuer, audience, or authorization validation has been established. |
| Malformed synthetic token: abc.def | Error: A compact JWT must contain a header, payload, and signature section. Earlier output is cleared. |
The tool does not verify signatures. Use your authentication library on the server to verify a token before trusting its claims.
These tools open separately; inputs are not transferred.
Convert Unix seconds or milliseconds to readable local and UTC dates.
Open tool →Pretty-print, minify, and validate JSON directly in your browser.
Open tool →Convert text to Base64 and back, entirely in your browser.
Open tool →Convert quoted CSV data into JSON arrays or objects locally.
Open tool →The token header and payload are decoded in your browser. The token is not uploaded to an Anvil processing server.
Decoding does not verify a signature, issuer, audience, expiry policy, or trust. A readable token can still be forged or invalid.
No. Anyone can decode a JWT. Trust it only after a server verifies the signature, accepted algorithm, issuer, audience, and relevant time claims.
No. Decoding happens entirely in your browser. Avoid sharing live access tokens with other people or services.
Remove a copied Bearer prefix and check that the sample has the expected dot-separated structure. Encrypted tokens require a different workflow. Use a harmless development token for support; successful decoding still does not verify the signature or grant access.
Changing a payload does not produce a valid signed token. A correctly configured server verifies the signature and claims before accepting it.
An ordinary signed JWT exposes readable header and payload data. This tool handles compact three-part tokens, not encrypted JWE messages. Never paste a live token into a support request.
Debug API Data with JSON, Base64, and Browser Tools
Work through JSON types, encoding, URL components, JWT claims, hashes, CSV conversion, and timestamps with small reproducible examples.