JWT Decoder
Inspect JWT headers and payloads locally. This tool does not verify signatures.
Decoded locally โ signature is not verified.
JWT
Header
Payload
What is a JWT?
A JSON Web Token (JWT), defined in RFC 7519, is a compact, URL-safe way to represent claims between two parties. A JWT has three segments separated by dots โ header.payload.signatureโ where the header names the signing algorithm, the payload carries the claims (data), and the signature lets a server verify the token hasn't been tampered with.
Each segment is Base64url-encoded JSON โ not standard Base64, so it uses -/_ instead of +//and typically drops padding, which is why pasting a raw JWT segment into a general Base64 decoder often fails. The payload's registered claims (RFC 7519 ยง4.1) include iss (issuer), sub (subject), aud (audience), and exp (expiration, a Unix timestamp) โ decoding eyJzdWIiOiIxMjM0NTY3ODkwIn0 reveals {"sub":"1234567890"}, for instance. Because decoding only reverses the encoding, this tool cannot tell you whether a token is genuine โ verifying the signature requires the issuer's secret or public key, which never leaves their server.
- Inspect an access or ID token from an OAuth/OIDC provider to confirm claims like
exp,aud, or a custom role claim without writing code - Debug why an API rejects a token โ for example checking the
exptimestamp for expiry or thealgin the header - Learn JWT structure by decoding sample tokens before integrating a JWT library
Also try the JSON formatter, JSON validator, JSON minifier, or JSON viewer.
JWT Decoder FAQ
- Does this tool verify the JWT signature?
- No. It decodes the header and payload only. Verifying a signature requires the issuer's secret or public key, which this browser-only tool never has access to.
- Why does decoding fail with an error?
- A JWT needs at least two dot-separated segments (header and payload). Extra whitespace, a truncated token, or a non-JWT string pasted in will fail to decode.
- What's the difference between the header and payload?
- The header names the signing algorithm and token type (e.g. HS256, JWT). The payload carries the actual claims โ data such as subject, issuer, and expiration.
- Is it safe to decode a real token here?
- Decoding happens entirely in your browser and the token is never sent anywhere. Still, treat tokens from production systems carefully โ anyone holding the raw token can read its payload.