JWT Decoder

Decode a JWT header and payload online for free, entirely in your browser.

Decoded locally. Signature verification is not performed.

How to use

  1. 1Paste a JWT into the box.
  2. 2View the decoded header and payload as formatted JSON.

Features

  • Decodes header and payload
  • Clearly states signature is not verified
  • Runs entirely in your browser

Supported formats

Input: JWTOutput: JSON

Privacy

Your token is decoded locally in your browser and is never sent to our server. Signature verification is not performed.

About this tool

The JWT Decoder splits a JSON Web Token into its header and payload sections and decodes each from Base64URL into readable JSON. It does not verify the token's signature, so it should not be used to confirm that a token is authentic — only to inspect its contents.

Frequently asked questions

Does this verify the JWT signature?

No. This tool only decodes the header and payload — it does not verify the signature, since that requires the signing secret or public key.

Is it safe to paste a production JWT here?

Decoding happens entirely in your browser and the token is never sent anywhere, but as a general rule avoid pasting real production tokens into any website.

Why does decoding fail for my token?

A JWT must have exactly three dot-separated, Base64URL-encoded parts. If any part isn't valid JSON once decoded, decoding will fail.