Developer tool / 13

JWT Decoder

Decode a JWT header and payload locally—with an explicit reminder that decoding is not verification.

JWT Decoder: TOEA Base64URL-decodes and parses the first two JWT segments; it does not use a key, issuer, or trust policy. Runs 100% locally in your browser with zero server file uploads.

Runs
In your browser
Cost
Free · no sign-up
Availability
Ready to use
JWT structure decoderLocal processing

Runs entirely in your browser

Decode only: this tool does not verify the signature or authenticity of a token.

Reading the claims

A JWT is three Base64URL parts separated by dots: a header naming the signing algorithm, a payload of claims, and a signature. The standard claims are iss (who issued it), sub (who it is about), aud (who it is for), and exp, iat, and nbf (when it expires, was issued, and becomes valid). The times are Unix seconds; the timestamp converter shows them as dates.

Decoding is not verifying

Anyone can create a token with any claims, so reading them proves nothing. The receiving service must check the signature with the right key, reject alg: none, and check the expiry, issuer, and audience. For tokens signed with a shared secret, the JWT verifier checks the signature.

The payload is only encoded, not encrypted: whoever holds the token can read it. Never put passwords or personal data in a JWT's claims.

How to use it

  1. Paste a three-segment JWT.
  2. Choose Decode token.
  3. Inspect the header, claims, and signature length.

Privacy & limitations

The token stays in your browser. Avoid pasting live credentials into any tool; decoding does not prove authenticity.

Related tools

Frequently asked questions

Does a decoded token mean it is valid?

No. Anyone can construct claims. Signature, issuer, audience, expiry, and policy must be verified by the receiving application.

Is the signature exposed?

The encoded signature segment and estimated byte length are shown, but it is not validated.

Free tool · runs in your browser · no account required