About JWT Decoder
Decode a JSON Web Token (JWT) to inspect its header and payload in readable JSON. See the claims, algorithm, and expiry — decoded entirely in your browser so tokens stay private.
How to Use
- Paste your JWT (the xxxxx.yyyyy.zzzzz string).
- The header and payload are Base64URL-decoded and shown as JSON.
- Inspect the claims, algorithm, and expiry.
- Nothing is sent anywhere — safe for real tokens.
Why Use This Tool?
- Accurate — built on precise, well-tested mathematical formulas.
- Instant — all calculations happen client-side for zero latency.
- Private — no data is sent to any server; your information stays on your device.
- Free — no sign-up, no limits, no hidden costs.
Frequently Asked Questions
Does decoding a JWT verify its signature?
No. Decoding only reads the header and payload, which are Base64-encoded, not encrypted. Verifying authenticity requires the secret or public key and is done server-side — never trust a decoded JWT without verifying it.
Is it safe to paste a real token here?
The decoding happens entirely in your browser and the token is never transmitted. That said, treat live tokens carefully and avoid pasting them into tools you don't trust.
Why can I read the payload without a key?
A JWT's header and payload are only Base64URL-encoded, not encrypted, so anyone can read them. The signature merely proves the token wasn't altered — it does not hide the contents.